S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 19, 2026

CVE-2022-0188 Scanner

CVE-2022-0188 Scanner - Broken Access Control vulnerability in CMP WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0188
5.3
CVSS

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
CMP
AFFECTED< 4.0.19SAFE ✓≥ 4.0.19
Updated Aug 22, 2026View on NVD →
Detail

CMP WordPress is a widely used plugin for the WordPress CMS, allowing website administrators to manage coming soon and maintenance page layouts. The plugin is popular among WordPress site owners for its ease of use and flexibility in design customizations. It is primarily used by web developers and administrators who need to put their sites temporarily offline for maintenance. CMP WordPress is often deployed in various web environments, ranging from personal blogs to large corporate websites. It provides features such as subscriber management, access control, and customizable themes. The plugin is distributed via the WordPress plugin repository and is frequently updated for new features and security improvements.

The broken access control vulnerability, in this case, is due to the plugin's failure to enforce proper permissions on the coming soon page feature. This flaw allows unauthenticated users to change the page layout, which can lead to various issues such as website defacement. Broken access control vulnerabilities are a common security issue, whereby users gain permissions they shouldn't have, leading to potentially severe security breaches. They are typically caused by incorrect or missing access control checks in the application's code. This particular vulnerability can be exploited without authentication, making it a critical issue for websites using the affected versions of the CMP WordPress plugin. Ensuring that access controls are correctly configured and implemented is essential to protect web applications from such vulnerabilities.

The vulnerability is present in the CMP WordPress plugin version 4.0.19 and earlier, specifically within the coming soon page feature. The technical flaw lies in the insufficient checking of user privileges, allowing unauthenticated users to access and modify settings intended only for site administrators. Attackers can exploit this vulnerability via a POST request to the affected endpoint. By doing so, they can alter the design and content of the "Coming Soon" page, affecting how site visitors perceive the website. The manipulation of the layout does not require valid credentials, thus enabling any remote user to exploit the flaw with the correct request parameters.

If exploited, this vulnerability can lead to misleading or defacement of a website's upcoming "Coming Soon" page. Attackers could potentially mislead visitors or damage the credibility of a website. Besides aesthetic damage, there could be financial or reputational repercussions for website owners. In more severe cases, a manipulated page could be used for phishing attacks or to distribute malware. Therefore, timely remediation of this vulnerability is critical to maintaining the integrity and security of affected websites. Users might find themselves victims of scams or malicious software if they interact with a compromised page.

REFERENCES

Solution Advice
  • Update the CMP WordPress plugin to version 4.0.19 or later.
  • Regularly audit plugin settings and conduct access control checks to ensure proper permissions.
  • Implement additional security measures such as firewalls and intrusion prevention systems to detect and prevent unauthorized access attempts.
  • Consider using WordPress security plugins to further bolster site security against access control vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.