CyberRota Analysis
AI-GeneratedThe CMP WordPress plugin prior to version 4.1.18 is vulnerable due to inadequate sanitization and escaping of settings values, enabling users with the Editor role to inject malicious scripts into the coming-soon page. This vulnerability could lead to cross-site scripting (XSS) attacks, potentially compromising site visitors. WordPress site administrators, particularly those using the CMP plugin with Editor role permissions, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.