---
id: CVE-2026-13413
title: >-
  The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not
  correctly restrict access to the site while maintenance/coming-soon mode is
  enabled, allowing unauthenticated visitors to bypass the coming-soon page and
  reach t…
summary: >-
  The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not
  correctly restrict access to the site while maintenance/coming-soon mode is
  enabled, allowing unauthenticated visitors to bypass the coming-soon page and
  reach t…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-284
product: CMP – Coming Soon & Maintenance
affected:
  - cmp_coming_soon_maintenance < 4.1.20
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:00:34.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13413'
references:
  - url: 'https://wpscan.com/vulnerability/706afdef-4935-44d9-ab09-68c80f3bfef9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00247
epssPercentile: 0.14503
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-02T10:48:49.378990Z'
ingestedAt: '2026-10-02T07:13:06.671Z'
---

## Overview

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
