WordPress Plugin RCE: CMP Coming Soon & Maintenance Vulnerability

WordPress Plugin RCE: CMP Coming Soon & Maintenance Vulnerability

The National Vulnerability Database has disclosed CVE-2026-6518, impacting the CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress. This critical vulnerability, present in all versions up to and including 4.1.16, allows for arbitrary file upload and remote code execution through the cmp_theme_update_install AJAX action. The root cause lies in insufficient capability checks and a severe lack of validation for user-supplied file URLs.

Specifically, the function validates against the publish_pages capability, which is accessible to Editors, rather than the more restrictive manage_options for Administrators. Coupled with no proper verification of the downloaded file’s content before extraction, an authenticated attacker with Administrator-level access can force the server to download a malicious ZIP file from a remote, attacker-controlled URL. This file is then extracted into a web-accessible directory (wp-content/plugins/cmp-premium-themes/), leading directly to remote code execution. While Editors possess the necessary capability, the absence of a nonce prevents them from exploiting this specific vector. The CVSS score for this vulnerability is a high 8.8.

This is a classic case of privilege escalation combined with a dangerous lack of input validation. Attackers understand that WordPress installations are often managed by multiple users with varying roles. Targeting a capability available to ‘Editors’ rather than strictly ‘Administrators’ significantly broadens the attack surface for internal threats or compromised accounts. The arbitrary file upload combined with code execution means full system compromise is trivial once an attacker gains initial access, even if it’s not administrative.

What This Means For You

  • If your organization uses the CMP – Coming Soon & Maintenance Plugin by NiteoThemes on your WordPress sites, you must prioritize patching to the latest secure version immediately. Audit your user roles and permissions; even if your Administrators are secure, a compromised Editor account could be leveraged if another exploit path is found, or if the nonce requirement is bypassed. Review logs for any unusual file uploads or modifications within `wp-content/plugins/cmp-premium-themes/`.

Related ATT&CK Techniques

🛡️ Detection Rules

3 rules · 6 SIEM formats

3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

critical T1190 Initial Access

WordPress CMP Plugin Arbitrary File Upload RCE - CVE-2026-6518

Sigma YAML — free preview
✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Export via Bot →

Indicators of Compromise

IDTypeIndicator
CVE-2026-6518 RCE CMP - Coming Soon & Maintenance Plugin by NiteoThemes for WordPress versions <= 4.1.16
CVE-2026-6518 Arbitrary File Upload Vulnerable AJAX action: `cmp_theme_update_install`
CVE-2026-6518 Privilege Escalation Insufficient capability check: `publish_pages` instead of `manage_options`
CVE-2026-6518 Code Injection Lack of validation on user-supplied file URL and no content verification before extraction
CVE-2026-6518 Information Disclosure Malicious ZIP file extracted to `wp-content/plugins/cmp-premium-themes/`
Source & Attribution
Source PlatformNVD
ChannelNational Vulnerability Database
PublishedApril 18, 2026 at 08:16 UTC

This content was AI-rewritten and enriched by Shimi's Cyber World based on the original source. All intellectual property rights remain with the original author.

Believe this infringes your rights? Submit a takedown request.

Related Posts

CVE-2026-41253 — Code Execution

CVE-2026-41253 — In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory...

vulnerabilityCVEmedium-severitycode-executioncwe-829
/SCW Vulnerability Desk /MEDIUM /⚑ 2 IOCs /⚙ 2 Sigma

Mirai Botnet Variants Target TBK DVRs via CVE-2024-3721

Mirai botnet variants, including Nexcorium, are actively exploiting a command injection vulnerability (CVE-2024-3721) in TBK DVR devices. This flaw, rated medium severity, allows attackers to...

threat-intelvulnerabilitymalwarecloud
/SCW Vulnerability Desk /HIGH /⚑ 1 IOC /⚙ 3 Sigma

CVE-2026-6048 — Cross-Site Scripting (XSS)

CVE-2026-6048 — The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in...

vulnerabilityCVEmedium-severitycross-site-scripting-xsscwe-79
/SCW Vulnerability Desk /MEDIUM /⚑ 2 IOCs /⚙ 3 Sigma