CMP WordPress plugin < 4.0.19 contains an arbitrary page layout change caused by insufficient access control in the coming soon page feature, letting unauthenticated users modify the layout, exploit requires no authentication.
id: CVE-2022-0188
info:
name: CMP WordPress < 4.0.19 - Broken Access Control
author: pussycat0x
...