CVE-2023-2159: CMP – Coming Soon & Maintenance <= 4.1.7 - Maintenance Mode Bypass
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmpbypass GET parameter in the URL (equal to the md5-hashed homeurl in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2159?
CVE-2023-2159 is considered a critical vulnerability as it allows unauthenticated users to bypass maintenance mode.
How do I fix CVE-2023-2159?
To fix CVE-2023-2159, upgrade the CMP – Coming Soon & Maintenance plugin to version 4.1.8 or later.
Who is affected by CVE-2023-2159?
CVE-2023-2159 affects users of the CMP – Coming Soon & Maintenance plugin for WordPress in versions 4.1.7 and earlier.
What type of vulnerability is CVE-2023-2159?
CVE-2023-2159 is classified as a maintenance mode bypass vulnerability.
Can CVE-2023-2159 allow unauthorized access?
Yes, CVE-2023-2159 allows unauthorized users to access a site that is meant to be in maintenance mode.