CVE-2026-13416
CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.
| Vendor | unknown |
| Product | cmp |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown cmp
Be the first to know when new unknown vulnerabilities affecting unknown cmp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / CMP
0 < 4.1.18
References
Credits
Revanth Hari Narayana Matte WPScan