Executive brief
The BoomDevs WordPress Coming Soon plugin is a tool that displays a holding page on WordPress sites under construction. An information disclosure vulnerability in versions up to 1.0.5 allows unauthenticated attackers to retrieve sensitive embedded data from the plugin, potentially exposing private information. This could compromise user credentials, email addresses, or other confidential data stored within the affected plugin.
Technical details
The vulnerability is a sensitive data exposure flaw (CWE-200 / CWE-452) in the BoomDevs WordPress Coming Soon plugin through version 1.0.5. The plugin fails to properly protect embedded sensitive information, allowing unauthenticated remote attackers to retrieve private data without authorization. This is a network-accessible vulnerability requiring no authentication or special privileges. An attacker can extract confidential information such as passwords, email addresses, or configuration details. No official patch is currently available according to Patchstack; users should update when available or disable the plugin if unable to patch.
Affected products
- BoomDevs WordPress Coming Soon <= 1.0.5
Timeline
- 2025-10-08: disclosed: Vulnerability reported by Jitlada
- 2025-12-31: advisory: Published by Patchstack