CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure
2023-03-07 00:00
Marco WotschkaStrategic Overview
StatusPatched in 4.1.7
Affected PluginCMP – Coming Soon & Maintenance Plugin by NiteoThemes
Affected Version
<= 4.1.6CVSS5.3Medium
CVE
CVE-2023-1263Vulnerability Overview
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
Technical Analysis
REMEDIATION: Update to version 4.1.7, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C