CVE Database /
CVE-2025-32118
CVE · Critical
CVE-2025-32118 — CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-32118
|
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.1
|
< 4.1.15
|
4.1.15 |
2025-04-04 |
—
|
CVE-2025-32118
The NiteoThemes CMP plugin for WordPress has a security flaw that allows authorized users with high-level permissions to upload any type of file without restriction in versions prior to 4.1.13. This vulnerability could potentially enable malicious files to be uploaded, leading to the possibility of remote code execution on the affected server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings