← WordPress Vulnerabilities
WordPress security by component

cmp

cmp displays customizable maintenance, coming-soon, and landing pages in WordPress.

cmp (cmp) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 27, 2026; the highest published CVSS base score is 8.3.

Plugin slug: cmp

CVE-2026-13416: CMP Editors can store script on the coming-soon page

CMP before 4.1.18 does not sanitize and escape a settings value before rendering it on the coming-soon page. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can store arbitrary script that executes for visitors who view the page.

PublishedAug 27, 2026
Known safe version4.1.18
Published vulnerabilities for cmp
Safe version
Aug 27, 2026 CVE-2026-13416
CMP Editors can store script on the coming-soon page
CMP before 4.1.18 does not sanitize and escape a settings value before rendering it on the coming-soon page. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can store arbitrary script that executes for visitors who view the page.
4.1.18
CVE3.5
NVDPending
Aug 27, 2026 CVE-2026-13415
CMP Editors can overwrite WordPress options and become Administrators
CMP before 4.1.18 does not enforce an option-name allow-list when importing settings through an AJAX action. When an administrator has granted Editors access to CMP's admin-bar controls, an Editor can overwrite arbitrary WordPress options, including options that permit privilege escalation to Administrator.
4.1.18
CVE7.2
NVDPending
Aug 27, 2026 CVE-2026-13414
CMP lets unauthenticated visitors disable maintenance mode
CMP before 4.1.18 omits authorization from an AJAX action and relies on a nonce that is skipped in some cases and exposed to anonymous visitors in others. Under a non-default countdown configuration, an unauthenticated attacker can disable the site's maintenance or coming-soon mode.
4.1.18
CVE4.8
NVDPending
Jun 07, 2023 CVE-2020-36730
Cmp: A security weakness
Cmp is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.3
NVD9.3
Feb 14, 2022 CVE-2022-0188
CMP: A security weakness
CMP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3