Redirect countdown - Cross-Site Request Forgery to Settings Update vulnerability
mediumCross-Site Request Forgery to Settings Update vulnerability
- CVSS:
- 4.3
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 23, 2026
plugin
2 known security issues reported for the Redirect Countdown WordPress plugin. Most recent disclosed Mar 23, 2026.
Running Redirect Countdown on your site? Check whether your installed version is affected.
Scan your site freeCross-Site Request Forgery to Settings Update vulnerability
The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the `countdown_settings_content()` function. This makes it possible for unauthenticated attackers to update the plugin settings including the coun...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free