Record summary

CVE-2023-1263 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Browse niteo / CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Default status: unaffected

CVE ListThrough 4.1.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMComing Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page AccessCVSS 5.3

The plugin does not restrict access to published and non protected posts/pages when the maintenance mode is enabled, allowing unauthenticated users to access them.

Impact

Unauthenticated attackers can bypass maintenance mode restrictions to access published posts and pages that should be protected during maintenance.

Remediation

Fixed in version 4.1.7

WeaknessesCWE-200
Authorsr3Y3r53
Template tagscvecve2023wordpresswpscanwp-pluginwpcmp-coming-soon-maintenanceunauthniteothemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:niteothemes:coming_soon_\&_maintenance:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/cmp-coming-soon-maintenance/
FOFA: body=/wp-content/plugins/cmp-coming-soon-maintenance/

Source: ProjectDiscovery

References

4