CVE-2023-2159
Summary
| CVE | CVE-2023-2159 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-09 06:16:00 UTC |
| Updated | 2023-11-07 04:12:00 UTC |
| Description | The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Niteothemes |
Cmp |
All |
All |
All |
All |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.