plugin

Countdown Builder Vulnerabilities

20 known security issues reported for the Countdown Builder WordPress plugin. Most recent disclosed Apr 3, 2025.

2 high 7 medium 1 low

Running Countdown Builder on your site? Check whether your installed version is affected.

Scan your site free

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion

high

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server,...

CVSS:
8.1
Affected:
up to 2.8.9.1
Fixed in:
2.9.0
Disclosed:
Apr 3, 2025

CVE-2025-2270 on NVD →

Countdown & Clock <= 2.8.8 - Authenticated (Contributor+) Remote Code Execution

high

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

CVSS:
8.8
Affected:
up to 2.8.8
Fixed in:
2.8.9
Disclosed:
Apr 1, 2025

CVE-2025-30841 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.8.9

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.

Affected:
up to 2.8.9
Fixed in:
2.8.9
Disclosed:
Apr 1, 2025

CVE-2025-30841 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] <= 2.9.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock allows Stored XSS.This issue affects Countdown & Clock: from n/a through 2.8.0.9.

Affected:
up to 2.9.3
Fix:
No patched version reported
Disclosed:
Nov 19, 2024

CVE-2024-50516 on NVD →

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 2.9.3
Fix:
No patched version reported
Disclosed:
Oct 28, 2024

CVE-2024-50516 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.7.8.1

unknown

[en] The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber...

Affected:
up to 2.7.8.1
Fixed in:
2.7.8.1
Disclosed:
Jun 6, 2024

CVE-2024-2017 on NVD →

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection

medium

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-leve...

CVSS:
5.4
Affected:
up to 2.7.8
Fixed in:
2.7.8.1
Disclosed:
Jun 5, 2024

CVE-2024-2017 on NVD →

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.9.5 - Authenticated Cross-Site Scripting

medium

The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Scripting. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:
5.5
Affected:
up to 2.3.9.5
Fixed in:
2.3.9.6
Disclosed:
May 25, 2022

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.3.9.6

unknown

The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Scripting. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected:
up to 2.3.9.6
Fixed in:
2.3.9.6
Disclosed:
May 25, 2022

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.3.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allows Stored XSS.This issue affects Countdown & Clock (WordPress plugin): from n/a through 2.3.2.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 6, 2022

CVE-2022-29420 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.3.3

unknown

[en] Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 6, 2022

CVE-2022-29421 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.3.3

unknown

[en] Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-l...

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 6, 2022

CVE-2022-29422 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.3.3

unknown

[en] Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
May 6, 2022

CVE-2022-29423 on NVD →

Countdown & Clock <= 2.3.2 - Pro Features Lock Bypass

low

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

CVSS:
3.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Apr 28, 2022

CVE-2022-29423 on NVD →

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.2 - Cross-Site Scripting

medium

Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-left,...

CVSS:
4.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Apr 28, 2022

CVE-2022-29422 on NVD →

Countdown & Clock <= 2.3.2 - Reflected Cross-Site Scripting

medium

Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.

CVSS:
6.1
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Apr 28, 2022

CVE-2022-29421 on NVD →

Countdown & Clock <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-circle-countdown-before-countdown and &ycd-circle-countdown-after-countdown vulnerable parameters.

CVSS:
5.5
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Apr 28, 2022

CVE-2022-29420 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.2.9

unknown

[en] The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Mar 14, 2022

CVE-2022-0601 on NVD →

Countdown & Clock <= 2.2.8 - Reflected Cross-Site Scripting

medium

The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVSS:
6.1
Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Feb 21, 2022

CVE-2022-0601 on NVD →

Countdown, Coming Soon, Maintenance &#8211; Countdown &amp; Clock [countdown-builder] < 2.9.0

unknown
Affected:
up to 2.9.0
Fixed in:
2.9.0

CVE-2025-2270 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database