📦

countdown_and_countup\,_woocommerce_sales_timer

Vendor: wpdevart

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.50% Exploit Prob.
Latest CVE CVE-2023-47533 Nov 14

Security Vulnerability Index

Page 1 / 1
5.9 CVSS

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Countdown and CountUp, WooCommerce Sales Timer plugin <= 1.8.2 versions.

EPSS: 0.39%
8.8 CVSS

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.

EPSS: 0.60%