Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown widget-countdown allows Stored XSS.This issue affects Widget Countdown: from n/a through <= 2.7.4.
Published: 2025-05-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The wpdevart Widget Countdown plugin contains a stored cross‑site scripting weakness that allows attackers to submit input without proper sanitization, which is then rendered on WordPress pages that contain the widget. Because the vulnerability is stored, the malicious script is persisted in the site’s database and executed in the browsers of anyone who views the affected widget, exposing browsers to arbitrary client‑side code.

Affected Systems

WordPress sites that have installed the Widget Countdown plugin version 2.7.4 or older are affected. The flaw exists in all releases through 2.7.4 and is resolved in later versions. Sites using the widget on public or private pages that are accessible to editors or administrators fall within the risk scope.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. The attack likely requires an attacker who can submit or modify widget content—such as a user with editor or administrator privileges—in order to inject the malicious script.

Generated by OpenCVE AI on May 2, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Widget Countdown plugin to a version newer than 2.7.4 as soon as an official fix is available.
  • If an update cannot be performed immediately, disable or remove the widget from all pages to prevent execution of stored scripts.
  • Review the plugin’s configuration and stored widget entries for unexpected content, and delete any entries that contain injected code before re‑enabling the widget.

Generated by OpenCVE AI on May 2, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13866 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown widget-countdown allows Stored XSS.This issue affects Widget Countdown: from n/a through <= 2.7.4.
Title WordPress Widget Countdown <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00039}

epss

{'score': 0.00045}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4.
Title WordPress Widget Countdown <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:41.274Z

Reserved: 2025-05-07T09:38:32.078Z

Link: CVE-2025-47443

cve-icon Vulnrichment

Updated: 2025-05-07T17:21:43.412Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:15:58.483

Modified: 2026-04-23T15:30:13.483

Link: CVE-2025-47443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:45:26Z

Weaknesses