The Events Calendar Countdown Addon <= 1.4.15 - Missing Authorization
medium
The The Events Calendar Countdown Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.4.15
- Fixed in:
- 1.4.16
- Disclosed:
- Jan 6, 2026
CVE-2025-69348 on NVD →
The Events Calendar Countdown Addon [countdown-for-the-events-calendar] <= 1.4.15 (unfixed)
unknown
[en] Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.15.
- Affected:
- up to 1.4.15
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-69348 on NVD →
The Events Calendar Countdown Addon [countdown-for-the-events-calendar] < 1.4.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolHappy The Events Calendar Countdown Addon allows Stored XSS. This issue affects The Events Calendar Countdown Addon: from n/a through 1.4.9.
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.10
- Disclosed:
- Jun 6, 2025
CVE-2025-49311 on NVD →
The Events Calendar Countdown Addon <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The The Events Calendar Countdown Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.10
- Disclosed:
- Jun 5, 2025
CVE-2025-49311 on NVD →
The Events Calendar Countdown Addon [countdown-for-the-events-calendar] <= 1.3.1
unknown
Arbitrary Plugin Installation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress The Events Calendar Countdown Addon plugin (versions <= 1.3.1).
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Apr 6, 2022
The Events Calendar Countdown Addon [countdown-for-the-events-calendar] <= 1.3.1
unknown
Arbitrary Plugin Activation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress The Events Calendar Countdown Addon plugin (versions <= 1.3.1).
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Apr 6, 2022
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
high
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
- CVSS:
- 8.8
- Affected:
- up to 1.3.1
- Fixed in:
- 1.4
- Disclosed:
- Apr 4, 2022
CVE-2022-4950 on NVD →
The Events Calendar Countdown Addon [countdown-for-the-events-calendar] < 1.4
unknown
Multiple plugins from the Cool Plugins vendor are missing capability and proper CSRF check in the cool_plugins_install and cool_plugins_activate AJAX actions, available to any authenticated users, allowing them to install and activate arbitrary plugins via an archive hosted on a remote server they control
- Affected:
- up to 1.4
- Fixed in:
- 1.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database