CVE-2026-12470 Details
Description
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
A vulnerability in the CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress allows authenticated attackers with Editor-level access and above to escalate privileges. This is due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in versions through 4.1.17. Exploitation of this vulnerability enables the unauthorized modification of data, specifically the ability to update arbitrary options on the WordPress site. Attackers could leverage this to change the default role for new user registrations to administrator, effectively gaining administrative access on the site.
Users are advised to update the CMP – Coming Soon & Maintenance Plugin by NiteoThemes to version 4.1.18 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NiteoThemes CMP - Coming Soon & Maintenance Plugin | <= 4.1.17 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion