Impact
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes has a missing capability check on the cmp_ajax_import_settings AJAX action, allowing any authenticated user with Editor privileges or higher to arbitrarily modify site options. By changing options such as the default user role to administrator or enabling user registration, an attacker can create new administrator accounts, effectively gaining full control of the WordPress site. This flaw represents improper privilege management (CWE-269) and jeopardizes confidentiality, integrity, and availability of the site data.
Affected Systems
All versions of the CMP – Coming Soon & Maintenance Plugin by NiteoThemes up to and including 4.1.17 are affected. The vulnerability is present in the plugin’s core code and can be exploited on any WordPress installation that has the vulnerable plugin active.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, but the EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers need only a valid authenticated session as an Editor or higher to trigger the exploit, which is a common role on many sites, making this a realistic risk scenario.
OpenCVE Enrichment