Impact
The WP Count Down Timer plugin is vulnerable to stored cross‑site scripting through several parameters of its shortcode, allowing an authenticated user with Contributor or higher access to inject arbitrary scripts. Such injected scripts will execute whenever the affected page is viewed, potentially compromising the confidentiality and integrity of the site and any users who view the page. The weakness stems from insufficient input sanitization and output escaping.
Affected Systems
All WordPress sites running WP Count Down Timer version 1.0.1 or earlier are affected. The plugin is distributed by sitedin under the name WP Count Down Timer.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access at the Contributor level or higher, but once the script is stored, it will affect any user who visits the injected page.
OpenCVE Enrichment