CVE-2026-6518
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
Minimum safe version
4.1.17
Update to 4.1.17 or later to address 14 fixable vulnerabilities
CVE-2025-32118
CVE-2023-50374
CVE-2020-36730
CVE-2023-2159
WordPress CMP – Coming Soon & Maintenance Plugin <= 4.1.6 is vulnerable to Sensitive Data Exposure
CMP <= 3.8.1 - Missing Authorization
CMP - Coming Soon & Maintenance < 3.8.2 - Improper Access Controls on AJAX Calls
WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Plugin Deactivation vulnerability
WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Subscribers List Export vulnerability
WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Arbitrary Post Read (draft, pending, private or even password-protected) vulnerability
WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Remote Code Execution (RCE) vulnerability
CVE-2022-0188