WordPress Plugin Vulnerabilities

CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax

Description

The plugin does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain themes (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 2 days ago)
Added
2026-08-25 (about 1 day ago)
Last Updated
2026-08-25 (about 1 day ago)

Other