CVE-2026-6518
The Coming Soon & Maintenance Plugin for WordPress is vulnerable to a serious security flaw that allows an authenticated attacker with Administrator-level access to upload arbitrary files to the server. This is because the plugin's update function does not properly validate the source of the files it downloads and extracts, and instead relies on the user's permissions to determine what actions are allowed. As a result, an attacker can trick the plugin into downloading and installing a malicious file from a remote location, allowing them to execute arbitrary code on the server.
Based on public CVE data (MITRE/NVD).