Skip to main content
Vulnerability Database/CVE-2026-12470

CVE-2026-12470: WordPress CMP Plugin Privilege Escalation

CVE-2026-12470 is a privilege escalation flaw in the CMP Plugin for WordPress that allows Editor-level attackers to modify site options and gain administrator access. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-12470 Overview

CVE-2026-12470 is a privilege escalation vulnerability in the CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress. The flaw affects all versions up to and including 4.1.17. The plugin fails to perform a capability check on the cmp_ajax_import_settings AJAX action, allowing authenticated users with Editor-level access or above to modify arbitrary WordPress options. Attackers can enable user registration and set the default registration role to administrator, granting themselves full administrative control of the site. The vulnerability is classified under [CWE-269: Improper Privilege Management].

Critical Impact

An authenticated Editor can escalate to administrator by modifying WordPress core options through an unprotected AJAX endpoint, leading to full site compromise.

Affected Products

  • CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress
  • All versions up to and including 4.1.17
  • WordPress sites with Editor-level or higher user accounts exposed

Discovery Timeline

  • 2026-09-22 - CVE-2026-12470 published to the National Vulnerability Database
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-12470

Vulnerability Analysis

The CMP – Coming Soon & Maintenance Plugin registers an AJAX action named cmp_ajax_import_settings intended to import plugin configuration. The handler processes attacker-controlled input and writes values to WordPress options without validating that the caller has administrator-level privileges. Because WordPress AJAX endpoints registered under wp_ajax_* only require a valid authenticated session, any user with wp-admin access, including Editors, can invoke the action. The handler exposes a general-purpose write primitive against the WordPress options table rather than restricting writes to plugin-scoped keys.

Root Cause

The root cause is a missing capability check in the AJAX handler at lines 3104 and 3143 of niteo-cmp.php in version 4.1.17. The function does not call current_user_can('manage_options') or an equivalent guard before writing to wp_options through update_option(). This omission constitutes improper privilege management as defined in [CWE-269]. A nonce alone is insufficient because Editors can retrieve valid nonces from the admin interface.

Attack Vector

An authenticated attacker with Editor privileges sends a crafted POST request to wp-admin/admin-ajax.php invoking the cmp_ajax_import_settings action. The payload sets the users_can_register option to 1 and the default_role option to administrator. The attacker then submits the standard WordPress registration form at wp-login.php?action=register to create a new administrator account. From that account, the attacker can install malicious plugins, execute arbitrary PHP, and pivot to the underlying host. Refer to the Wordfence Vulnerability Report and the WordPress Plugin Code Review for the vulnerable handler.

Detection Methods for CVE-2026-12470

Indicators of Compromise

  • POST requests to /wp-admin/admin-ajax.php containing action=cmp_ajax_import_settings from non-administrator sessions.
  • Unexpected changes to the users_can_register or default_role values in the wp_options table.
  • New administrator accounts created shortly after suspicious AJAX activity.
  • Installation of unfamiliar plugins or themes immediately following account creation.

Detection Strategies

  • Inspect web server access logs for cmp_ajax_import_settings requests and correlate the source session with the requesting user role.
  • Audit the wp_options table for out-of-band modifications to registration-related keys.
  • Enable WordPress audit logging plugins to track option updates and user role changes.

Monitoring Recommendations

  • Alert on any change to users_can_register and default_role outside of scheduled maintenance windows.
  • Monitor for administrator account creation events and validate them against a change control record.
  • Track plugin and theme installations initiated by newly created accounts.

How to Mitigate CVE-2026-12470

Immediate Actions Required

  • Update the CMP – Coming Soon & Maintenance Plugin to a version above 4.1.17 as published in the WordPress Plugin Changeset.
  • Review all administrator accounts and remove any that were not provisioned by authorized personnel.
  • Reset credentials for all Editor-level and higher accounts.
  • Verify the users_can_register and default_role options match the intended configuration.

Patch Information

NiteoThemes released a fix in the version following 4.1.17. The patch adds a capability check to the cmp_ajax_import_settings handler. Site administrators should apply the update through the WordPress plugin manager or by installing the current release from the official plugin repository. See the WordPress Plugin Changeset for the committed fix.

Workarounds

  • Deactivate and remove the CMP – Coming Soon & Maintenance Plugin until the patch is applied.
  • Restrict Editor-level access to trusted users only and review current role assignments.
  • Deploy a web application firewall rule that blocks POST requests to admin-ajax.php containing action=cmp_ajax_import_settings from non-administrator sessions.
  • Set define('DISALLOW_FILE_MODS', true); in wp-config.php to limit post-exploitation plugin and theme installation.
bash
# Configuration example: hardening wp-config.php against post-exploitation
define('DISALLOW_FILE_MODS', true);
define('DISALLOW_FILE_EDIT', true);

# Verify registration settings via WP-CLI
wp option get users_can_register
wp option get default_role
wp option update users_can_register 0
wp option update default_role subscriber

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.