Impact
The vulnerability arises from the Countdown Timer for Elementor plugin permitting stored cross‑site scripting through the 'countdown_label' field. Improper input sanitization ensures that an attacker can embed malicious JavaScript that is persisted and executed whenever any user views a page containing the injected timer. This flaw grants attackers arbitrary client‑side code execution, compromising visitor confidentiality and potentially enabling credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79.
Affected Systems
The affected component is the Countdown Timer for Elementor WordPress plugin. All versions up to and including 1.3.9 are vulnerable. The plugin is distributed by shaikhaezaz80 and can be found under the "Countdown Timer for Elementor" category in the WordPress plugin repository.
Risk and Exploitability
It is inferred from the CVE description that attackers can inject malicious payloads via the 'countdown_label' field. While the exact path is not explicitly spelled out, it is likely that the attack vector involves the timer widget editing interface, requiring authenticated Contributor or higher access. Once the payload is stored, the script runs automatically for any visitor accessing the affected page, multiplying the impact across all site users. The CVSS score of 6.4 denotes moderate severity. The EPSS score of less than 1% indicates that the likelihood of exploitation by known actors is low at this time, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD