Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1.
Published: 2025-12-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input in the MX Time Zone Clocks plugin, allowing stored cross‑site scripting. The CVE description specifies that malicious scripts can be stored and later executed in browsers of users who view the affected content. The description does not explicitly state that attackers could hijack sessions, deface the site, or exfiltrate data; such outcomes are common with XSS but are inferred rather than confirmed.

Affected Systems

The vulnerability affects the Maksym Marko MX Time Zone Clocks WordPress plugin, specifically all releases up to and including version 5.1.1. Users running these versions are subject to the described risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, and the EPSS score of less than 1% suggests a low probability of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is inferred: an attacker who can create or edit plugin input that is stored and rendered (for example, through a configuration form or an admin comment) could insert malicious code; when other users view the affected page, the script executes. The specific privileges required are not detailed in the CVE data, but stored XSS generally needs write access to input fields the plugin processes. While the CVE does not detail consequences beyond stored XSS, typical effects such as session hijack or defacement are inferred.

Generated by OpenCVE AI on April 30, 2026 at 04:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MX Time Zone Clocks plugin to a version newer than 5.1.1.
  • If an update is not yet available, disable the plugin to eliminate the affected code path.
  • Clear or purge all MX Time Zone Clocks data from the WordPress database to remove any stored malicious payloads.

Generated by OpenCVE AI on April 30, 2026 at 04:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through 5.1.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through 5.1.1.
Title WordPress MX Time Zone Clocks plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:02.935Z

Reserved: 2025-10-07T15:41:52.360Z

Link: CVE-2025-62146

cve-icon Vulnrichment

Updated: 2025-12-31T16:03:36.357Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T09:15:51.307

Modified: 2026-04-23T15:34:37.647

Link: CVE-2025-62146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:45:06Z

Weaknesses