VulnerabilityModified
CVE-2022-0188
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
MEDIUM 5.3EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- niteothemes/cmp
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2657597/cmp-coming-soon-maintenancePatch, Third Party Advisory
- https://wpscan.com/vulnerability/50b6f770-6f53-41ef-b2f3-2a58e9afd332Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2657597/cmp-coming-soon-maintenancePatch, Third Party Advisory
- https://wpscan.com/vulnerability/50b6f770-6f53-41ef-b2f3-2a58e9afd332Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.