Description
The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.
No analysis available yet.
Remediation
Vendor Solution
Update plugin to version 1.5.8 or newer.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21286 | The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7. |
References
History
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-31T18:12:13.099Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34636
Updated: 2024-08-04T00:19:47.639Z
Status : Modified
Published: 2021-09-28T14:15:07.897
Modified: 2024-11-21T06:10:51.740
Link: CVE-2021-34636
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD