CVE-2022-0188

Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.


We have discovered 752 live websites that are affected by CVE-2022-0188.

Run a Free Instant Scan




Affected Software

Product  Cmp Coming Soon Maintenance
Category Wordpress Plugins
Vulnerable Domains752 live websites (9.06% of Cmp Coming Soon Maintenance install base)
Vulnerable Versions
  • from 0 through 4.0.19
Vulnerable Versions Count62 versions ( 77% of all versions)


Common Weakness Enumeration

CWE-306 Missing Authentication for Critical Function



Details

  • Published - Feb 14, 2022
  • Updated - Aug 2, 2024

Credits

  • Krzysztof Zając (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2022-0188
United States112 websites



Germany160 websites
Italy77 websites
France48 websites
GB47 websites
Netherlands26 websites
Spain21 websites
Denmark19 websites
Poland17 websites
South Africa13 websites

Website Distribution by TLD

Number of websites using CVE-2022-0188
.com261 websites
.de93 websites
.it59 websites
.co.uk32 websites
.nl23 websites
.net16 websites
.fr14 websites
.at13 websites
.pl13 websites
.be11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-0188

Top websites that are affected by CVE-2022-0188. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org France***,***
*****.at Austria*,***,***
****************.net GB*,***,***
******************.com United States*,***,***
******.com United States*,***,***
************************.org France*,***,***
**************.de Germany*,***,***
************.net Germany*,***,***
*****.es Spain*,***,***
************.ru Russia*,***,***
See full domain list

FAQ

CVE-2022-0188 is Missing Authentication for Critical Function in Cmp Coming Soon Maintenance
A total of 752 websites have been identified as vulnerable to CVE-2022-0188, based on global website indexing conducted by WebTechSurvey.
The Cmp Coming Soon Maintenance is affected by the CVE-2022-0188 vulnerability.
Cmp Coming Soon Maintenance versions up to 4.0.19 are vulnerable to CVE-2022-0188.
CVE-2022-0188 is resolved in version 4.0.19 of Cmp Coming Soon Maintenance.