VYPR

CMP

by WordPress

CVEs (5)

  • CVE-2020-36730HigJun 7, 2023
    risk 0.54cvss 8.3epss 0.02

    The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated…

  • CVE-2026-13415HigAug 27, 2026
    risk 0.47cvss 7.2epss 0.00

    The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's…

  • CVE-2022-0188MedFeb 14, 2022
    risk 0.35cvss 5.3epss 0.02

    The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

  • CVE-2026-13414MedAug 27, 2026
    risk 0.31cvss 4.8epss 0.00

    The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's…

  • CVE-2026-13416LowAug 27, 2026
    risk 0.23cvss 3.5epss 0.00

    The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's…