Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion
high
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server,...
- CVSS:
- 8.1
- Affected:
- up to 2.8.9.1
- Fixed in:
- 2.9.0
- Disclosed:
- Apr 3, 2025
CVE-2025-2270 on NVD →
Countdown & Clock <= 2.8.8 - Authenticated (Contributor+) Remote Code Execution
high
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
- CVSS:
- 8.8
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- Apr 1, 2025
CVE-2025-30841 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.8.9
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- Apr 1, 2025
CVE-2025-30841 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] <= 2.9.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock allows Stored XSS.This issue affects Countdown & Clock: from n/a through 2.8.0.9.
- Affected:
- up to 2.9.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 19, 2024
CVE-2024-50516 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 2.9.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 28, 2024
CVE-2024-50516 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.7.8.1
unknown
[en] The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber...
- Affected:
- up to 2.7.8.1
- Fixed in:
- 2.7.8.1
- Disclosed:
- Jun 6, 2024
CVE-2024-2017 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection
medium
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-leve...
- CVSS:
- 5.4
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8.1
- Disclosed:
- Jun 5, 2024
CVE-2024-2017 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.9.5 - Authenticated Cross-Site Scripting
medium
The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Scripting. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 5.5
- Affected:
- up to 2.3.9.5
- Fixed in:
- 2.3.9.6
- Disclosed:
- May 25, 2022
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.3.9.6
unknown
The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Scripting. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected:
- up to 2.3.9.6
- Fixed in:
- 2.3.9.6
- Disclosed:
- May 25, 2022
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.3.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allows Stored XSS.This issue affects Countdown & Clock (WordPress plugin): from n/a through 2.3.2.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 6, 2022
CVE-2022-29420 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.3.3
unknown
[en] Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 6, 2022
CVE-2022-29421 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.3.3
unknown
[en] Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-l...
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 6, 2022
CVE-2022-29422 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.3.3
unknown
[en] Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- May 6, 2022
CVE-2022-29423 on NVD →
Countdown & Clock <= 2.3.2 - Pro Features Lock Bypass
low
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
- CVSS:
- 3.8
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 28, 2022
CVE-2022-29423 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.2 - Cross-Site Scripting
medium
Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd-progress-height, &ycd-progress-width, &ycd-button-margin-top, &ycd-button-margin-right, &ycd-button-margin-bottom, &ycd-button-margin-left,...
- CVSS:
- 4.8
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 28, 2022
CVE-2022-29422 on NVD →
Countdown & Clock <= 2.3.2 - Reflected Cross-Site Scripting
medium
Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 28, 2022
CVE-2022-29421 on NVD →
Countdown & Clock <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-circle-countdown-before-countdown and &ycd-circle-countdown-after-countdown vulnerable parameters.
- CVSS:
- 5.5
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 28, 2022
CVE-2022-29420 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.2.9
unknown
[en] The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
- Disclosed:
- Mar 14, 2022
CVE-2022-0601 on NVD →
Countdown & Clock <= 2.2.8 - Reflected Cross-Site Scripting
medium
The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
- CVSS:
- 6.1
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
- Disclosed:
- Feb 21, 2022
CVE-2022-0601 on NVD →
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.9.0
unknown
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
CVE-2025-2270 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database