Junglewise Threat Intelligence

CVE-2026-13414: CMP Coming Soon & Maintenance missing authorization in AJAX action

CVE-2026-13414 · Severity: medium · CVSS 4.8 · Published 2026-08-27

Executive brief

CMP is a WordPress plugin that manages site maintenance and coming-soon pages, displaying them to visitors when enabled. An unauthenticated attacker can disable the maintenance mode entirely by sending a single web request to the plugin's unprotected AJAX endpoint, causing a protected site to go public without administrator action. This affects sites using specific builder themes (Divi, Elementor, Oxygen Builder) with countdown functionality configured.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the plugin's cmp_disable_comingsoon_ajax AJAX action. The plugin relies on WordPress nonces for CSRF protection, but when certain builder themes (Divi, Elementor, Oxygen Builder) are selected with countdown mode enabled, the nonce validation is skipped entirely. An unauthenticated attacker can send a POST request to wp-admin/admin-ajax.php with action=cmp_disable_comingsoon_ajax&status=disable-cmp to flip the niteoCS_status option from "on" to "0", immediately disabling the maintenance/coming-soon page. No authentication, cookies, or valid nonce are required. The issue is scoped to three specific builder themes; other CMP themes enforce the nonce check and are not vulnerable. The plugin maintainers patched this in version 4.1.18.

Affected products

  • Automatic CMP - Coming Soon & Maintenance before 4.1.18

Timeline

  • 2026-08-25: disclosed
  • 2026-08-27: advisory
  • 2026-08-25: patched: Fixed in version 4.1.18

References