CVE-2026-13413
Received Received - Intake

CMP Plugin Maintenance Mode Bypass Vulnerability

Vulnerability report for CVE-2026-13413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder cmp_coming_soon_and_maintenance to 4.1.20 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The CMP – Coming Soon & Maintenance WordPress plugin before version 4.1.20 has a flaw where unauthenticated visitors can bypass the maintenance or coming-soon mode by crafting requests that appear as login attempts. This allows them to access hidden parts of the site, including published pages that should remain restricted during maintenance.

Detection Guidance

Check if the CMP – Coming Soon & Maintenance WordPress plugin version is below 4.1.20. You can do this by logging into your WordPress admin panel, navigating to Plugins, and looking for the plugin version. Alternatively, use WP-CLI with the command: wp plugin list --name='cmp-coming-soon-and-maintenance' to check the installed version.

Impact Analysis

This vulnerability allows unauthorized users to view private or restricted content on your WordPress site while it is in maintenance or coming-soon mode. This could expose sensitive information, drafts, or pages meant to be hidden from public access.

Mitigation Strategies

Update the CMP – Coming Soon & Maintenance plugin to version 4.1.20 or later immediately. If updating is not possible, consider temporarily disabling the plugin until an update can be applied. Ensure your WordPress site is not in maintenance or coming-soon mode during this process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart