CVE-2026-13414
CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.
| Vendor | unknown |
| Product | cmp |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown cmp
Be the first to know when new unknown vulnerabilities affecting unknown cmp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / CMP
0 < 4.1.18
References
Credits
Revanth Hari Narayana Matte WPScan