Description
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.
Published: 2026-08-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The CMP WordPress plugin in versions prior to 4.1.18 fails to restrict the set of option names that can be imported through an AJAX call. An editor who has been given access to the plugin via the admin‑bar controls can use this endpoint to update any WordPress option value, including those that control user roles or capabilities. By altering these options an attacker can elevate a user from Editor to Administrator, effectively gaining full control over the site.

Affected Systems

The vulnerability affects the CMP WordPress plugin, any site that has installed this plugin with a version earlier than 4.1.18. The impact is confined to installations where the site administrator has granted the Editor role permission to use the CMP WordPress plugin’s admin‑bar controls.

Risk and Exploitability

The flaw can be exploited remotely by presenting an authenticated request to the plugin’s AJAX endpoint. No code execution is required beyond the Editor role. The CVSS score of 7.2 indicates high severity. The EPSS score of <1% and the lack of listing in CISA’s KEV catalog imply a low probability of exploitation, yet the vulnerability still allows an attacker to elevate to Administrator if Editor access is granted to the CMP plugin’s admin‑bar interface. Once elevated, full control of the WordPress site can be achieved, making this a critical risk for affected installations.

Generated by OpenCVE AI on August 27, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CMP WordPress plugin to version 4.1.18 or later.
  • Revoke Editor role access to the CMP plugin’s admin‑bar interface until the patch is applied.
  • Monitor WordPress option changes and review the role and capability settings after applying the patch to ensure no unauthorized modifications remain.

Generated by OpenCVE AI on August 27, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-269

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.
Title CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-27T14:23:49.069Z

Reserved: 2026-06-26T11:40:15.631Z

Link: CVE-2026-13415

cve-icon Vulnrichment

Updated: 2026-08-27T14:15:37.701Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T06:16:55.537

Modified: 2026-08-28T18:43:25.883

Link: CVE-2026-13415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T17:30:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management