Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer countdown-time allows Stored XSS.This issue affects Countdown Timer: from n/a through <= 1.2.6.
Published: 2025-02-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin’s input fields are not properly sanitized before rendering, allowing attackers to store malicious JavaScript within the block. When a visitor views a page containing the compromised block, the script runs in the victim’s browser, providing the attacker with the ability to hijack sessions, steal sensitive data, deface content, or launch further attacks. This vulnerability is a classic example of CWE‑79 and can leak confidential information or alter the user experience by executing arbitrary code.

Affected Systems

All WordPress installations running the Countdown Timer plugin from the earliest released version up through version 1.2.6 are affected. The vendor, bPlugins, does not specify a minimum vulnerable version, so any site with 1.2.6 or earlier should assume risk.

Risk and Exploitability

The CVSS base score of 6.5 classifies the flaw as medium severity, while an EPSS score of less than 1 % indicates a currently low likelihood of exploitation in the wild. The vulnerability is listed in no KEV catalog, reducing immediate operational exposure. Exploitation requires that an attacker can inject content into the block, typically through an administrative or author account, but once stored it can affect all site visitors. Given the moderate score and low EPSS, the danger is contingent on whether the plugin remains unpatched and the site’s user roles allow content manipulation.

Generated by OpenCVE AI on May 1, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Countdown Timer plugin to a version newer than 1.2.6 or apply any security update released by bPlugins.
  • If an upgrade is not immediately feasible, disable or remove the Countdown Timer block plugin from all sites to eliminate the vulnerable code path.
  • Consider implementing a content security policy and a web‑application firewall rule that blocks common XSS payloads, particularly in block content submitted by users.

Generated by OpenCVE AI on May 1, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer: from n/a through 1.2.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer: from n/a through 1.2.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer countdown-time allows Stored XSS.This issue affects Countdown Timer: from n/a through <= 1.2.6.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 25 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer: from n/a through 1.2.6.
Title WordPress Countdown Timer block plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:44.304Z

Reserved: 2025-02-17T11:51:18.743Z

Link: CVE-2025-26938

cve-icon Vulnrichment

Updated: 2025-02-25T15:06:21.688Z

cve-icon NVD

Status : Deferred

Published: 2025-02-25T15:15:27.747

Modified: 2026-06-17T09:02:38.143

Link: CVE-2025-26938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')