CVE-2023-1263
CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure
Record summary
CVE-2023-1263 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CMP – Coming Soon & Maintenance Plugin by NiteoThemesBrowse niteo / CMP – Coming Soon & Maintenance Plugin by NiteoThemesDefault status: unaffected | CVE List | Through 4.1.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMComing Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page AccessCVSS 5.3
The plugin does not restrict access to published and non protected posts/pages when the maintenance mode is enabled, allowing unauthenticated users to access them.
Impact
Unauthenticated attackers can bypass maintenance mode restrictions to access published posts and pages that should be protected during maintenance.
Remediation
Fixed in version 4.1.7
Source: ProjectDiscovery