Junglewise Threat Intelligence

CVE-2026-13415: CMP Coming Soon & Maintenance privilege escalation via settings import

CVE-2026-13415 · Severity: high · CVSS 7.2 · Published 2026-08-27

Executive brief

CMP is a WordPress plugin that manages maintenance and coming-soon pages for websites. A flaw in its settings import feature allows users with the Editor role to escalate their privileges to Administrator by changing arbitrary WordPress configuration options, including who can register and their default role. An attacker with Editor access (if the admin has granted it) can register new accounts as Administrators or modify other critical settings without authorization.

Technical details

The vulnerability is a privilege escalation via improper access control in the plugin's AJAX action cmp_ajax_import_settings. The plugin fails to enforce an option-name allow-list when importing settings, allowing authenticated users with the Editor role to update arbitrary WordPress options through a POST request containing a malicious JSON payload. The attack requires the administrator to have explicitly granted the Editor role access to the plugin's admin-bar controls (an opt-in feature documented in CMP Settings > CMP Advanced Setup). By replaying a valid AJAX nonce extracted from the admin bar, an Editor-level user can set options like default_role to "administrator" and enable user registration, leading to full privilege escalation. The vulnerability is fixed in version 4.1.18.

Affected products

  • CMP Coming Soon & Maintenance before 4.1.18

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in version 4.1.18

References