SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13414

MEDIUM · CVSS 4.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The CMP WordPress plugin prior to version 4.1.18 is vulnerable due to a lack of proper authorization checks on specific AJAX actions, which can be exploited by unauthenticated attackers. This flaw allows malicious users to disable the site's maintenance or coming-soon mode, potentially exposing sensitive content or disrupting site operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13414
Severity
MEDIUM
CVSS
4.8
EPSS
0.14%
WordPress

Original NVD Description

The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.