CVE-2026-13416 PUBLISHED

CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia

Assigner: WPScan
Reserved: 26.06.2026 Published: 27.08.2026 Updated: 27.08.2026

The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

Product Status

Vendor Unknown
Product CMP
Versions Default: unaffected
  • affected from 0 to 4.1.18 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE