Impact
The CMP WordPress plugin before version 4.1.18 fails to sanitize and escape a settings value that is rendered on the Coming‑Soon page. An Editor user who has permission to edit the plugin via the admin‑bar can inject arbitrary JavaScript into that value. When any visitor accesses the Coming‑Soon page the injected script executes with the visitor’s browser context, enabling defacement, theft of session cookies, and malicious redirects. The flaw is a stored XSS that persists until the plugin is updated or the value is removed.
Affected Systems
All WordPress sites that install the CMP plugin with any version older than 4.1.18 are affected, regardless of other plugins or themes. The vulnerability is exploitable only on sites that grant Editor‑role users access to the CMP settings in the WordPress admin‑bar.
Risk and Exploitability
Because the flaw can be introduced by any Editor, which is a typical role for content authors, the risk is high. The vulnerability remains unlisted in the CISA KEV catalog and its EPSS score is presently unavailable, but the stored XSS nature and the potential for cross‑site attacks suggest a high likelihood of exploitation once discovered. The attack vector concentrates on the public‑facing Coming‑Soon page, where the malicious code runs for every visitor to the site.
OpenCVE Enrichment