Description
The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Bypass of Maintenance Mode
Action: Immediate Patch
AI Analysis

Impact

The CMP – Coming Soon & Maintenance WordPress plugin fails to enforce its maintenance or coming‑soon mode, allowing an unauthenticated user to shape a request that the plugin mistakenly interprets as a login attempt, thereby bypassing the restricted mode and revealing hidden site content. This flaw is primarily an improper access control issue (CWE-284) that exposes content that should remain hidden during planned downtime.

Affected Systems

WordPress sites that use the CMP – Coming Soon & Maintenance plugin with a version earlier than 4.1.20 are affected; no specific WordPress core versions are mentioned, so the flaw resides solely in the plugin. Administrators should verify the installed plugin version to confirm risk.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability represents moderate risk; the EPSS score is not available, so the likelihood of exploitation is unknown. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a web‑based request sent by an unauthenticated visitor, crafted to match the plugin’s login URL pattern while the site is in maintenance mode.

Generated by OpenCVE AI on October 2, 2026 at 08:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CMP – Coming Soon & Maintenance plugin to version 4.1.20 or later, which applies the access‑control fix.
  • If an upgrade cannot be performed immediately, temporarily disable or remove the CMP plugin to prevent the bypass while maintaining a valid site over the downtime period.
  • Configure a web application firewall or .htaccess rule to deny all incoming requests that are not authenticated during maintenance mode, ensuring that only legitimate traffic can reach the site.

Generated by OpenCVE AI on October 2, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.
Title CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:11.054Z

Reserved: 2026-06-26T11:40:04.990Z

Link: CVE-2026-13413

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:45.855Z

cve-icon NVD

Status : Received

Published: 2026-10-02T07:16:36.040

Modified: 2026-10-02T11:17:33.013

Link: CVE-2026-13413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses