Improper access control in CMP - Coming Soon & Maintenance Plugin by NiteoThemes - #VU33677
Published: August 4, 2020
CMP - Coming Soon & Maintenance Plugin by NiteoThemes
NiteoThemes
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "niteo_export_csv" AJAX action. A remote authenticated attacker can bypass implemented security restrictions and download the plugin’s subscribers list which includes email addresses and names.