Impact
The CMP – Coming Soon & Maintenance WordPress plugin fails to enforce its maintenance or coming‑soon mode, allowing an unauthenticated user to shape a request that the plugin mistakenly interprets as a login attempt, thereby bypassing the restricted mode and revealing hidden site content. This flaw is primarily an improper access control issue (CWE-284) that exposes content that should remain hidden during planned downtime.
Affected Systems
WordPress sites that use the CMP – Coming Soon & Maintenance plugin with a version earlier than 4.1.20 are affected; no specific WordPress core versions are mentioned, so the flaw resides solely in the plugin. Administrators should verify the installed plugin version to confirm risk.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability represents moderate risk; the EPSS score is not available, so the likelihood of exploitation is unknown. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a web‑based request sent by an unauthenticated visitor, crafted to match the plugin’s login URL pattern while the site is in maintenance mode.
OpenCVE Enrichment