WordPress Plugin Vulnerabilities

Countdown and CountUp, WooCommerce Sales Timers < 1.5.8 - CSRF to Stored Cross-Site Scripting

Description

The plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Xu-Liang Liao
Verified
No

Timeline

Publicly Published
2021-09-27 (about 4 years ago)
Added
2021-09-27 (about 4 years ago)
Last Updated
2022-04-14 (about 4 years ago)

Other