Impact
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin contains a Local File Inclusion flaw in the createCdObj function. Unauthenticated users can supply a path to an existing file on the server, causing the plugin to read and execute that file as PHP code. This gives the attacker the ability to run arbitrary PHP, bypass access controls, extract sensitive data, or establish persistence. The flaw is classified as CWE‑22.
Affected Systems
Any WordPress site using the Countdown, Coming Soon, Maintenance – Countdown & Clock plugin version 2.8.9.1 or earlier is affected. The plugin is distributed by adamskaat; all releases up to and including 2.8.9.1 contain the vulnerability. Newer releases should be verified for a fix.
Risk and Exploitability
The CVSS score is 8.1, indicating a high severity. The EPSS score is below 1 %, suggesting a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a request that manipulates the createCdObj function’s input to include a file on the server, enabling unauthenticated remote code execution. Without remediation, the risk remains significant.
OpenCVE Enrichment
EUVD