Niteothemes develops WordPress plugins focused on e-commerce and site-management functionality, with its vulnerability footprint centered on authentication and access-control weaknesses in products such as its Coming Soon & Maintenance and CMP plugins. The recurring exposure pattern—spanning sensitive-information disclosure, improper access control, and missing authentication or authorization for critical functions—reflects common risks in third-party WordPress plugin development where authentication boundaries and privilege enforcement are frequently overlooked. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Niteothemes over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36730CRITICAL The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() fu | Jun 7, 2023 | 9.3 | 29 | NO | NO |
CVE-2023-1263MEDIUM The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This c | Mar 7, 2023 | 5.3 | 27 | NO | YES |
CVE-2022-0188MEDIUM The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. | Feb 14, 2022 | 5.3 | 25 | NO | YES |
CVE-2023-2159MEDIUM The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the | Jun 9, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Niteothemes.
Media articles that mention a CVE ID that affects a product developed by Niteothemes — matched by CVE ID, not by vendor name.