The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability che…
High CVSS 7.2
Summary
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://plugins.trac.wordpress.org/browser/cmp-coming-soon-maintenance/tags/4.1.17/niteo-cmp.php#L3104
- https://plugins.trac.wordpress.org/browser/cmp-coming-soon-maintenance/tags/4.1.17/niteo-cmp.php#L3143
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3661069%40cmp-coming-soon-maintenance&new=3661069%40cmp-coming-soon-maintenance
- https://www.wordfence.com/threat-intel/vulnerabilities/id/20e2f410-72a9-4d94-b80d-1cb625c08962?source=cve
Timeline
- nvd_ingest NVD