CVE-2020-36730
The CMP – Coming Soon & Maintenance plugin for WordPress through version 3.8.1 fails to properly verify user permissions before executing certain functions, allowing unauthenticated users to access restricted capabilities. Attackers without valid credentials could read post content, download subscriber data as CSV files, and disable the plugin entirely by exploiting missing authorization checks in the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions. This vulnerability was resolved in version 3.8.2.
Based on public CVE data (MITRE/NVD).