Improper access control in CMP - Coming Soon & Maintenance Plugin by NiteoThemes - #VU33676
Published: August 4, 2020
CMP - Coming Soon & Maintenance Plugin by NiteoThemes
NiteoThemes
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "cmp_get_post_detail" AJAX action. A remote attacker can bypass implemented security restrictions and view any post or page, including those that are marked as draft, pending, private or even password-protected.