Data Modification Vulnerability in CMP – Coming Soon & Maintenance Plugin by NiteoThemes
CVE-2026-12470
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-12470?
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress has a vulnerability that allows authenticated users, particularly those with Editor-level access, to exploit a missing capability check on the 'cmp_ajax_import_settings' AJAX action. This oversight can lead to unauthorized data modification, enabling attackers to alter critical site settings, such as elevating user roles to administrator and allowing unauthorized user registration. This vulnerability poses a significant risk for WordPress sites utilizing the affected plugin versions.
Affected Version(s)
CMP – Coming Soon & Maintenance Plugin by NiteoThemes 0 <= 4.1.17