PT-2026-33590 · Niteothemes · Cmp – Coming Soon & Maintenance Plugin
Published
2026-04-18
·
Updated
2026-04-19
·
CVE-2026-6518
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMP – Coming Soon & Maintenance Plugin by NiteoThemes versions prior to 4.1.17
Description
The plugin allows arbitrary file upload and remote code execution through the 'cmp theme update install' AJAX action. The issue occurs because the
cmp theme update install() function verifies the publish pages capability instead of the manage options capability, and fails to validate the user-supplied file URL or the content of the downloaded file before extraction. Authenticated attackers with Administrator-level access can force the server to download and extract a malicious ZIP file from a remote URL into the 'wp-content/plugins/cmp-premium-themes/' directory, leading to remote code execution.Recommendations
Update the plugin to a version later than 4.1.16.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmp – Coming Soon & Maintenance Plugin