Information Exposure Vulnerability in CMP – Coming Soon & Maintenance Plugin for WordPress
CVE-2023-1263

5.3MEDIUM

What is CVE-2023-1263?

The CMP – Coming Soon & Maintenance plugin for WordPress contains a vulnerability that allows unauthorized individuals to access the contents of any non-password-protected, published post or page. This issue arises from the cmp_get_post_detail function, which fails to properly restrict access, even when the site is in maintenance mode. Consequently, sensitive information could be exposed to the public, raising serious security concerns for website administrators.

Affected Version(s)

CMP – Coming Soon & Maintenance Plugin by NiteoThemes 0 <= 4.1.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Wotschka
.