CyberRota Analysis
AI-GeneratedThe CMP WordPress plugin prior to version 4.1.18 is vulnerable due to a lack of proper authorization checks on specific AJAX actions, which can be exploited by unauthenticated attackers. This flaw allows malicious users to disable the site's maintenance or coming-soon mode, potentially exposing sensitive content or disrupting site operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.