Skip to content
Critical RCE Vulnerability in WordPress Plugin CVE-2026-6518

Critical RCE Vulnerability in WordPress Plugin CVE-2026-6518

First seen 19 Apr 2026, 07:45 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 20, 2026 at 07:27 UTC
  • •CVE-2026-6518 allows RCE via the CMP plugin for WordPress, affecting versions up to 4.1.16.
  • •Authenticated users with Administrator access can exploit this vulnerability due to improper capability checks.
  • •No patch is available; restrict access and monitor for suspicious activity related to the AJAX action.

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress has a critical vulnerability (CVE-2026-6518) affecting all versions up to 4.1.16. This vulnerability allows authenticated users with Administrator privileges to exploit the `cmp_theme_update_install` AJAX action, which improperly checks user capabilities, enabling arbitrary file uploads and remote code execution. Attackers can force the server to download and extract malicious ZIP files into a web-accessible directory, leading to full server compromise. Editors cannot exploit this vulnerability due to nonce protections. No patch or official fix has been released as of April 19, 2026. Security professionals are advised to restrict Administrator access and monitor for suspicious activity. Currently, there are no known exploits in the wild. The vulnerability was published on April 18, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 174d ago How this analysis works

Timeline

2026-04-18
CVE-2026-6518 published
2026-04-19
Vulnerability reported in multiple cybersecurity articles

More articles in this cluster (2)

Following this threat?

Track CVE-2026-6518 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed