{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cmp--coming-soon--maintenance-plugin--4.1.17/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:niteothemes:cmp_coming_soon_maintenance_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-12470"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CMP – Coming Soon \u0026 Maintenance Plugin (\u003c= 4.1.17)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application","cms"],"_cs_type":"advisory","_cs_vendors":["NiteoThemes"],"content_html":"\u003cp\u003eThe CMP - Coming Soon \u0026amp; Maintenance Plugin by NiteoThemes for WordPress is susceptible to an unauthenticated privilege escalation vulnerability tracked as CVE-2026-12470. The vulnerability exists within the 'cmp_ajax_import_settings' AJAX action, which fails to perform necessary capability checks before processing user-supplied data. This allows an authenticated user with Editor-level access or higher to perform unauthorized modifications to the WordPress site's configuration. By manipulating global options, such as the default user role and registration settings, an attacker can elevate their own privileges or create new administrative accounts, ultimately gaining full control over the affected WordPress installation. This issue impacts all plugin versions up to and including 4.1.17.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid credentials for an account with Editor-level permissions on the target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the WordPress dashboard using the compromised credentials.\u003c/li\u003e\n\u003cli\u003eAttacker identifies that the CMP plugin is installed and active on the site.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the 'admin-ajax.php' endpoint with the 'cmp_ajax_import_settings' action.\u003c/li\u003e\n\u003cli\u003eThe request body includes JSON-encoded payload values designed to modify core 'wp_options' table entries.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request without validating the user's capability, updating the site settings to enable 'users_can_register' and setting the 'default_role' to 'administrator'.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the public registration page to create a new user account, which is automatically assigned the administrator role upon creation.\u003c/li\u003e\n\u003cli\u003eAttacker logs in with the newly created administrator account to achieve full site takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12470 results in total compromise of the affected WordPress site. An attacker can gain administrative access, potentially leading to the installation of malicious plugins, backdoored themes, data exfiltration, or the defacement of the website. Any site running the CMP plugin up to version 4.1.17 is considered at high risk of unauthorized administrative account creation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of the CMP - Coming Soon \u0026amp; Maintenance Plugin to a patched version beyond 4.1.17 as provided by NiteoThemes.\u003c/p\u003e\n\u003cp\u003eFor security operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor 'wp-admin/admin-ajax.php' access logs for POST requests containing 'cmp_ajax_import_settings' that originate from non-administrative accounts.\u003c/li\u003e\n\u003cli\u003eAudit the 'wp_options' table for sudden changes to the 'default_role' and 'users_can_register' keys.\u003c/li\u003e\n\u003cli\u003eReview all administrative accounts created recently to ensure they are legitimate.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T06:33:33Z","date_published":"2026-09-22T06:33:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cmp-plugin-priv-esc/","summary":"The CMP - Coming Soon \u0026 Maintenance Plugin is vulnerable to privilege escalation due to an unauthenticated AJAX setting import that allows authenticated editors to modify arbitrary site options.","title":"Privilege Escalation in CMP - Coming Soon \u0026 Maintenance Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-cmp-plugin-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - CMP – Coming Soon \u0026 Maintenance Plugin (\u003c= 4.1.17)","version":"https://jsonfeed.org/version/1.1"}