Junglewise Threat Intelligence

CVE-2026-12470: NiteoThemes CMP Coming Soon & Maintenance missing capability check

CVE-2026-12470 · Severity: high · CVSS 7.2 · Published 2026-09-22

Executive brief

A WordPress plugin used to display coming-soon and maintenance pages contains a privilege escalation vulnerability. An Editor-level user can exploit a missing permission check to modify site settings, including enabling user registration and changing the default role to administrator, thereby gaining full administrative access to the WordPress site.

Technical details

The 'cmp_ajax_import_settings' AJAX action lacks a capability check, allowing authenticated Editor+ users to call it and update arbitrary WordPress options without authorization. An attacker can modify wp_user_default_role to "administrator" and enable user_registration, then register a new account that receives admin privileges, resulting in complete site compromise.

Affected products

  • NiteoThemes CMP – Coming Soon & Maintenance Plugin up to and including 4.1.17

Timeline

  • 2026-09-22: disclosed

References