Authorization Bypass Vulnerability in CMP WordPress Plugin
CVE-2026-13414

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-13414?

The CMP WordPress plugin prior to version 4.1.18 is susceptible to an authorization bypass vulnerability due to inadequate checks on several AJAX actions. This flaw allows unauthenticated attackers to bypass intended restrictions and disable the maintenance or coming-soon mode. Notably, some actions rely on a nonce mechanism that is incorrectly leveraged or entirely omitted for certain requests. As a consequence, the integrity of countdown configuration can be compromised, exposing sites to potential disruptions.

Affected Version(s)

CMP 0 < 4.1.18

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Revanth Hari Narayana Matte
WPScan
.