Description
The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
Published: 2026-09-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross-site Scripting via unchecked skin class attribute
Action: Patch Immediately
AI Analysis

Impact

The CoolClock WordPress plugin versions before 4.3.8 do not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. Because the malicious code is stored, all subsequent views of the content by any site visitor will execute the script.

Affected Systems

WordPress sites using the CoolClock plugin version 4.3.8 or older. All installations are vulnerable; newer releases are safe.

Risk and Exploitability

a CVSS score of 6.8, as any JavaScript can be executed in the context of users who view the polluted content. The exploit requires a contributor or higher account on the WordPress site, a privilege that is often available to many content editors. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. An attacker therefore must compromise the site or obtain a contributor account to place the payload, though the stored nature allows it to affect all users after the injection.

Generated by OpenCVE AI on September 11, 2026 at 14:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CoolClock plugin to version 4.3.8 or later as soon as possible.
  • If an upgrade cannot be performed immediately, delete the skin setting that contains unescaped data or disable the skin feature entirely until a patched version is available.
  • Restrict contributor-level access to trusted personnel only, and regularly audit role assignments to ensure that only authorized users have permission to alter plugin settings.

Generated by OpenCVE AI on September 11, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
Title CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:11:46.329Z

Reserved: 2026-08-31T18:05:52.974Z

Link: CVE-2026-83546

cve-icon Vulnrichment

Updated: 2026-09-11T10:05:39.438Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:47.050

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-83546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')