WordPress Plugin Vulnerabilities

CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia

Description

The plugin does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the plugin's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-25 (about 2 days ago)

Other