nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0188 CVE-2022-0188
MEDIUMNuclei
Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update
Record summary
CVE-2022-0188 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CMPDefault status: unaffected | CVE List | Before 4.0.19 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMCMP WordPress < 4.0.19 - Broken Access Control
CMP WordPress plugin < 4.0.19 contains an arbitrary page layout change caused by insufficient access control in the coming soon page feature, letting unauthenticated users modify the layout, exploit requires no authentication.
Impact
Unauthenticated users can alter the coming soon page layout, potentially misleading visitors or causing defacement.
Remediation
Update to version 4.0.19 or later.
Authorspussycat0x
Template tagscvecve2022wp-scanwordpresswp-plugincmpintrusive
Shodan: html:"wp-content/plugins/cmp-coming-soon-maintenance"
Source: ProjectDiscovery
References
3plugins.trac.wordpress.orgpatch
https://plugins.trac.wordpress.org/changeset/2657597/cmp-coming-soon-maintenance wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/50b6f770-6f53-41ef-b2f3-2a58e9afd332