Impact
The vulnerability is a stored cross‑site scripting flaw (CWE‑79) that allows an attacker to inject malicious scripts into data that is later rendered by the WPC Countdown Timer for WooCommerce plugin. If an attacker succeeds, the injected script runs in the browser context of any user who views the affected page, potentially enabling client‑side manipulation.
Affected Systems
The affected vendor is WPClever and the product is the WPC Countdown Timer for WooCommerce plugin. Versions up to and including 3.1.4 are vulnerable; any installation of the plugin where the version is 3.1.4 or older must be treated as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker injecting malicious payload through the plugin’s input mechanisms that store data; the attacker may need the ability to edit or create content within the WordPress site. Once stored, the payload executes whenever the impacted data is displayed.
OpenCVE Enrichment