Sceawere

Vulnerability Detail

CVE-2026-13413UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CMP Plugin Access Control Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
16h ago
Vendor
Unknown
Product
CMP – Coming Soon & Maintenance
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T07:16:36.040Z",
  "pubdate": "2026-10-02T07:16:36.040Z",
  "executiveSummary": "The CMP – Coming Soon & Maintenance WordPress plugin, in versions prior to 4.1.20, contains a critical access control vulnerability. This flaw allows unauthenticated attackers to bypass the intended maintenance or coming-soon page, effectively rendering the site's protective measures ineffective. By manipulating HTTP requests to mimic legitimate authentication attempts, unauthorized users can gain unrestricted access to private or hidden site content. This vulnerability exposes sensitive administrative areas or unpublished pages to the public, potentially leading to unauthorized information disclosure. The issue poses a significant risk to site security and data privacy, as it completely negates the access restrictions that administrators rely on during site development or maintenance phases. Exploitation does not require prior authentication, making this an accessible target for remote attackers seeking to bypass site-wide security controls.",
  "technicalDetails": "The vulnerability resides within the request handling logic of the CMP – Coming Soon & Maintenance plugin, specifically in how the plugin determines whether to enforce the coming-soon/maintenance restriction or allow the request to proceed to the core WordPress application. The root cause is an insecure implementation of access control checks that fails to correctly validate the nature of incoming requests. The plugin identifies legitimate login attempts as a means to exempt specific traffic from the maintenance page filter; however, this mechanism is susceptible to request manipulation.\nThe attack flow commences when an unauthenticated attacker submits a specifically crafted HTTP request. By shaping the request parameters or headers to mimic the structure and intent of an authentication or login-related request, the attacker triggers the plugin's validation logic incorrectly. The plugin erroneously classifies these malicious requests as authorized access attempts, thereby suppressing the maintenance page response and allowing the request to be processed by the underlying WordPress engine.\nOnce the filter is bypassed, the attacker can traverse and access content that is normally protected, including published pages intended for hidden viewing or sensitive site areas that should be inaccessible while in maintenance mode. This effectively circumvents the security boundaries established by the plugin. The vulnerable component is the traffic interception and validation module responsible for toggling the display of the coming-soon page. The vulnerability is present in all versions of the CMP plugin before 4.1.20 and is reachable over the network without the requirement for any valid session or administrative privilege. Successful exploitation results in the complete loss of confidentiality regarding the site's hidden structure and content, potentially facilitating further reconnaissance for more severe vulnerabilities."
}
CVE-2026-13413: CMP Plugin Access Control Bypass (MEDIUM Severity, CVSS: 5.3) | Sceawere