Extension WordPress

Vulnérabilités CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Cette page rassemble les failles publiées pour CMP – Coming Soon & Maintenance Plugin by NiteoThemes, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CMP – Coming Soon & Maintenance Plugin by NiteoThemes

7 fiches

CVE-2026-6518 Élevée · 8,8
CMP – Coming Soon & Maintenance Plugin by NiteoThemes

CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 – Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is…

Versions affectées

*-4.1.16

Correctif

4.1.17

Publication

17/04/2026

CVE-2025-32118 Élevée · 7,2
CMP – Coming Soon & Maintenance Plugin by NiteoThemes

CMP – Coming Soon & Maintenance <= 4.1.13 – Authenticated (Admin+) Arbitrary File Upload

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.13. This makes it possible for…

Versions affectées

*-4.1.13

Correctif

4.1.15

Publication

04/04/2025

CVE-2023-50374 Moyenne · 5,5
CMP – Coming Soon & Maintenance Plugin by NiteoThemes

CMP – Coming Soon & Maintenance <= 4.1.10 – Authenticated (Admin+) Server-Side Request Forgery

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.10. This makes it possible for authenticated attackers, with administrator-level access and…

Versions affectées

*-4.1.10

Correctif

4.1.11

Publication

27/03/2024

CVE-2023-1263 Moyenne · 5,3
CMP – Coming Soon & Maintenance Plugin by NiteoThemes

CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 – Information Exposure

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected,…

Versions affectées

*-4.1.6

Correctif

4.1.7

Publication

07/03/2023

CVE-2020-36730 Élevée · 8,3
CMP – Coming Soon & Maintenance Plugin by NiteoThemes

CMP <= 3.8.1 – Missing Authorization

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read…

Versions affectées

*-3.8.1

Correctif

3.8.2

Publication

04/08/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités