Detects the CMP Coming Soon & Maintenance Plugin (NiteoThemes) for WordPress in versions up to and including 4.1.16 where the cmp_theme_update_install AJAX handler accepts a fully attacker-controlled file URL, downloads the ZIP from any host, and extracts it into a web-accessible directory without rejecting PHP entries. The capability check is publish_pages instead of manage_options. An authenticated user with a valid plugin nonce (in practice an Administrator) can drop a PHP webshell into wp-content/plugins/cmp-premium-themes/ and execute arbitrary code. The fix in 4.1.17 raises the capability check, forces the download URL through a hostname allowlist, and rejects ZIPs containing .php, .phtml, or .phar entries.
Is your app exploitable through CVE-2026-6518?
Scan your domain free