WordPress security by component
cmp
Plugin description
cmp displays customizable maintenance, coming-soon, and landing pages in WordPress.
cmp (cmp) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 27, 2026; the highest published CVSS base score is 8.3.
Plugin slug:
cmpLatest vulnerability
CVE-2026-13416: CMP Editors can store script on the coming-soon page
CMP before 4.1.18 does not sanitize and escape a settings value before rendering it on the coming-soon page. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can store arbitrary script that executes for visitors who view the page.
| Safe version |
|
||
|---|---|---|---|
| Aug 27, 2026 |
CVE-2026-13416
CMP Editors can store script on the coming-soon page
CMP before 4.1.18 does not sanitize and escape a settings value before rendering it on the coming-soon page. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can store arbitrary script that executes for visitors who view the page.
|
4.1.18 |
CVE3.5
NVDPending
|
| Aug 27, 2026 |
CVE-2026-13415
CMP Editors can overwrite WordPress options and become Administrators
CMP before 4.1.18 does not enforce an option-name allow-list when importing settings through an AJAX action. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can overwrite arbitrary WordPress options, including options that permit privilege escalation to Administrator.
|
4.1.18 |
CVE7.2
NVDPending
|
| Aug 27, 2026 |
CVE-2026-13414
CMP lets unauthenticated visitors disable maintenance mode
CMP before 4.1.18 omits authorization from an AJAX action and relies on a nonce that is skipped in some cases and exposed to anonymous visitors in others. Under a non-default countdown configuration, an unauthenticated attacker can disable the site's maintenance or coming-soon mode.
|
4.1.18 |
CVE4.8
NVDPending
|
| Jun 07, 2023 |
CVE-2020-36730
Cmp: A security weakness
Cmp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.3
NVD9.3
|
| Feb 14, 2022 |
CVE-2022-0188
CMP: A security weakness
CMP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.3
|