S4E just found a medium-severity finding from backup files scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-1263 Scanner

CVE-2023-1263 scanner - Unauthenticated Post/Page Access vulnerability in Coming Soon & Maintenance

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CMP – Coming Soon & Maintenance Plugin by NiteoThemesby niteo
0
Updated Sep 18, 2026View on NVD →
Detail

The Coming Soon & Maintenance plugin for WordPress is designed to help website owners put their site in maintenance or coming soon mode while they make updates or changes. This plugin is widely used by website administrators to display a maintenance or coming soon page to visitors while keeping the site accessible to the admin for updates. It offers customizable templates and design options to create aesthetically pleasing maintenance pages that inform visitors about the current status of the website. The plugin is popular among WordPress users for its ease of use and functionality in managing site visibility during updates or development phases.

CVE-2023-1263 identifies a vulnerability in the Coming Soon & Maintenance plugin versions prior to 4.1.7, where the plugin fails to restrict access to published and non-protected posts/pages even when the maintenance mode is enabled. This oversight allows unauthenticated users to access content that should be hidden from view, bypassing the intended functionality of the maintenance mode. This vulnerability exposes website content to unauthorized access, potentially leading to information disclosure.

The flaw is rooted in the plugin's inability to properly enforce access controls when the maintenance mode is activated. Unauthenticated users can request post or page details through an AJAX call without any authentication or authorization checks, leading to unauthorized access to content that should otherwise be inaccessible. This issue is a result of inadequate security measures within the plugin's codebase, particularly in handling AJAX requests for post/page details.

Exploitation of this vulnerability can lead to unauthorized access to website content, including potentially sensitive information that was not intended for public view. This could undermine the privacy and security of the website's data and damage the website owner's reputation. Additionally, it may lead to information leakage that could be leveraged for further attacks against the website or its users.

Joining the S4E platform offers website owners and administrators a proactive approach to identifying and mitigating vulnerabilities like CVE-2023-1263. Our platform provides detailed vulnerability assessments and actionable recommendations to secure your digital assets effectively. By becoming a member, you gain access to a suite of tools designed to enhance your website's security posture, helping you to maintain the confidentiality, integrity, and availability of your online presence.

 

References

Solution Advice
  1. Update the Coming Soon & Maintenance plugin to version 4.1.7 or later to address this vulnerability.
  2. Regularly review and update all WordPress plugins and themes to their latest versions.
  3. Implement additional access control measures to restrict access to sensitive content during maintenance periods.
  4. Consider using a web application firewall (WAF) to monitor and block suspicious requests to your website.
  5. Conduct periodic security audits to identify and remediate potential vulnerabilities in your website's plugins and themes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-1263 scanner - Unauthenticated Post/Page Access vulnerability in Coming Soon & Maintenance | S4E