CVE · High

CVE-2020-36730 — CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36730 CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 Missing Authorization High 8.3 < 3.8.2 3.8.2 2020-08-04

CVE-2020-36730

The CMP – Coming Soon & Maintenance plugin for WordPress through version 3.8.1 fails to properly verify user permissions before executing certain functions, allowing unauthenticated users to access restricted capabilities. Attackers without valid credentials could read post content, download subscriber data as CSV files, and disable the plugin entirely by exploiting missing authorization checks in the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions. This vulnerability was resolved in version 3.8.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.