
BREAKING: Critical RCE CVE-2026-6518 hits CMP Coming Soon & Maintenance WordPress plugin versions up to 4.1.16, enabling admin-level arbitrary file upload, no patch available. https://threatcluster.io/cluster/critical-rce-vulnerability-in-wordpress-plugin-cve-2026-6518-09ad35ab
Post summary
This tweet announces the discovery of CVE‑2026‑6518, a critical RCE in the CMP Coming Soon & Maintenance WordPress plugin that enables arbitrary file uploads, with no patch available.



