The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
We have discovered 1,416 live websites that are affected by CVE-2023-1263.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,416 live websites (17% of Cmp Coming Soon Maintenance install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 71 versions ( 88% of all versions) |
| 223 websites | |
| 302 websites | |
| 125 websites | |
| 86 websites | |
| 83 websites | |
| 54 websites | |
| 46 websites | |
| 31 websites | |
| 31 websites | |
| 30 websites |
| .com | 491 websites |
| .de | 168 websites |
| .it | 92 websites |
| .nl | 49 websites |
| .co.uk | 49 websites |
| .org | 30 websites |
| .net | 29 websites |
| .es | 29 websites |
| .fr | 28 websites |
| .at | 27 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | ***,*** | ||
| ******.com | ***,*** | ||
| ******.org | *,***,*** | ||
| *****.at | *,***,*** | ||
| *********.hr | *,***,*** | ||
| ****************.net | *,***,*** | ||
| *******.at | *,***,*** | ||
| ******************.com | *,***,*** | ||
| *************.com | *,***,*** | ||
| *************.pl | *,***,*** |
FAQ