### [CVE-2022-0188](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0188) ![](https://img.shields.io/static/v1?label=Product&message=CMP&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%204.0.19%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-306%20Missing%20Authentication%20for%20Critical%20Function&color=brighgreen) ### Description The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. ### POC #### Reference - https://wpscan.com/vulnerability/50b6f770-6f53-41ef-b2f3-2a58e9afd332 #### Github - https://github.com/ARPSyndicate/cvemon