The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmpbypass GET parameter in the URL (equal to the md5-hashed homeurl in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmpgetpostdetail(), niteoexportcsv(), and cmpdisablecomingsoonajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.