CVE-2023-1263: CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmpgetpostdetail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1263?
CVE-2023-1263 has a medium severity rating due to its potential for exposing sensitive information.
How do I fix CVE-2023-1263?
To fix CVE-2023-1263, update the CMP – Coming Soon & Maintenance plugin to version 4.1.7 or higher.
What type of vulnerability is CVE-2023-1263?
CVE-2023-1263 is classified as an Information Exposure vulnerability.
Who is affected by CVE-2023-1263?
CVE-2023-1263 affects users of the CMP – Coming Soon & Maintenance plugin for WordPress versions up to 4.1.6.
What can attackers do with CVE-2023-1263?
Attackers can exploit CVE-2023-1263 to gain unauthorized access to the contents of published posts or pages that are not password protected.