All verified exploits

CVE-2026-6518 Admin File Upload to RCE via CMP Coming Soon & Maintenance

Deterministic high WordPress Added cve-verified-cve-2026-6518

Detects the CMP Coming Soon & Maintenance Plugin (NiteoThemes) for WordPress in versions up to and including 4.1.16 where the cmp_theme_update_install AJAX handler accepts a fully attacker-controlled file URL, downloads the ZIP from any host, and extracts it into a web-accessible directory without rejecting PHP entries. The capability check is publish_pages instead of manage_options. An authenticated user with a valid plugin nonce (in practice an Administrator) can drop a PHP webshell into wp-content/plugins/cmp-premium-themes/ and execute arbitrary code. The fix in 4.1.17 raises the capability check, forces the download URL through a hostname allowlist, and rejects ZIPs containing .php, .phtml, or .phar entries.

Related WordPress exploits

Is your app exploitable through CVE-2026-6518?

Scan your domain free