Critical RCE Vulnerability in WordPress Plugin CVE-2026-6518
Article Content
- •CVE-2026-6518 allows RCE via the CMP plugin for WordPress, affecting versions up to 4.1.16.
- •Authenticated users with Administrator access can exploit this vulnerability due to improper capability checks.
- •No patch is available; restrict access and monitor for suspicious activity related to the AJAX action.
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes for WordPress has a critical vulnerability (CVE-2026-6518) affecting all versions up to 4.1.16. This vulnerability allows authenticated users with Administrator privileges to exploit the `cmp_theme_update_install` AJAX action, which improperly checks user capabilities, enabling arbitrary file uploads and remote code execution. Attackers can force the server to download and extract malicious ZIP files into a web-accessible directory, leading to full server compromise. Editors cannot exploit this vulnerability due to nonce protections. No patch or official fix has been released as of April 19, 2026. Security professionals are advised to restrict Administrator access and monitor for suspicious activity. Currently, there are no known exploits in the wild. The vulnerability was published on April 18, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-6518 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…