Access violation vulnerability in CMP – Coming Soon & Maintenance Plugin by NiteoThemes 3.8.1

The Content Management System (CMS) for WordPress, called Content Management Platform (CMP), is at risk of being bypassed without proper authorization. This is because the versions of CMP up to 3.8.1 do not have the right security measures in place for the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions. As a result, it is possible for people who have not been authorized to access the system to read posts, export subscriber lists, and disable the plugin.

Detected in:

CMP – Coming Soon & Maintenance Plugin by NiteoThemes fixed vulnerable versions: >= * <= 3.8.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.