'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2025-32118:WordPress plugin CMP – Coming Soon & Maintenance Arbitrary File Upload Vulnerability
Severity:critical
CVE ID:CVE-2025-32118
| Descripiton:
|
WordPress and WordPress plugins are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. This platform supports the setup of personal blog websites on servers running PHP and MySQL. A WordPress plugin is an application plugin. The WordPress plugin CMP – Coming Soon & Maintenance version 4.1.13 and earlier have a code issue vulnerability. This vulnerability stems from allowing the upload of dangerous file types. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.