WordPress Plugin Vulnerabilities
CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match
Description
The plugin does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-29 (about 3 days ago)
Added
2026-09-29 (about 2 days ago)
Last Updated
2026-09-29 (about 2 days ago)