750
VMScore

CVE-2025-26938

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.00046 | KEV: Not Included
Published: 25/02/2025 Updated: 25/02/2025

Vulnerability Summary

Stored Cross-Site Scripting Vulnerability in bPlugins Countdown Timer <= 1.2.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer: from n/a up to and including 1.2.6.

Solution

Update the WordPress Countdown Timer wordpress plugin to the latest available version (at least 1.2.7).
Vulnerable Product Search on Vulmon Subscribe to Product

bplugins countdown timer