← back
CVE-2022-0188

Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 2.3%
exploitation probability
2.3%top 18% of all CVEs
observed exploitation
nono source reports it
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
Affected products
Unknown · CMP