CVE-2022-0188: vulnerability in CMP
Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update
Published · Updated
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 2.3%
exploitation probability
2.3%top 17% of all CVEs
observed exploitation
nono source reports it
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
Affected products
Unknown · CMPRelated CVEs — CMP
In the same product, most dangerous first.
CVE-2026-13415HIGHCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settingsEPSS 0.2%CVE-2026-13414MEDIUMCMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajaxEPSS 0.1%CVE-2026-13416LOWCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmediaEPSS 0.1%