Record summary

CVE-2022-0188 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

CMP

Default status: unaffected

CVE ListBefore 4.0.19affected

Nuclei templates

1
ProjectDiscoveryMEDIUMCMP WordPress < 4.0.19 - Broken Access Control

CMP WordPress plugin < 4.0.19 contains an arbitrary page layout change caused by insufficient access control in the coming soon page feature, letting unauthenticated users modify the layout, exploit requires no authentication.

Impact

Unauthenticated users can alter the coming soon page layout, potentially misleading visitors or causing defacement.

Remediation

Update to version 4.0.19 or later.

Authorspussycat0x
Template tagscvecve2022wp-scanwordpresswp-plugincmpintrusive
Shodan: html:"wp-content/plugins/cmp-coming-soon-maintenance"

Source: ProjectDiscovery

References

3