plugin

Waiting Vulnerabilities

15 known security issues reported for the Waiting WordPress plugin. Most recent disclosed Oct 20, 2023.

2 high 3 medium

Running Waiting on your site? Check whether your installed version is affected.

Scan your site free

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

[en] The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Oct 20, 2023

CVE-2022-4954 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

[en] The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to create and delete countdowns, via forged requ...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Aug 31, 2023

CVE-2023-4000 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

[en] The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns a...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Aug 31, 2023

CVE-2023-3999 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

[en] The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
May 18, 2023

CVE-2023-2757 on NVD →

Waiting: One-click countdowns <= 0.6.2 - Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting

high

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for s...

CVSS:
7.4
Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
May 17, 2023

CVE-2023-2757 on NVD →

Waiting: One-click countdowns <= 0.6.2 - Authenticated (Subscriber+) SQL Injection via 'pbc_down[meta][id]'

high

The Waiting: One-click countdowns plugin for WordPress is vulnerable to time-based SQL Injection via the ‘pbc_down[meta][id]’ parameter of the pbc_save_downs AJAX action in versions up to, and including, 0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...

CVSS:
8.8
Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Mar 22, 2023

CVE-2023-28659 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

[en] The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Mar 22, 2023

CVE-2023-28659 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

No patched version available. Wordfence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Waiting: One-click countdowns Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a passwo...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 26, 2022

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

No patched version available. Wordfence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Waiting: One-click countdowns Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be exec...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 26, 2022

Waiting: One-click countdowns <= 0.6.2 - Missing Authorization

medium

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as wel...

CVSS:
6.3
Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

CVE-2023-3999 on NVD →

Waiting: One-click countdowns <= 0.6.2 - Cross-Site Request Forgery

medium

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to create and delete countdowns, via forged request g...

CVSS:
6.3
Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

CVE-2023-4000 on NVD →

Waiting: One-click countdowns <= 0.6.2 - Authenticated (Administrator+) Cross-Site Scripting

medium

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abov...

CVSS:
5.5
Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

CVE-2022-4954 on NVD →

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as wel...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abov...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

Waiting: One-click countdowns [waiting] <= 0.6.2 (unfixed + closed)

unknown

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to create and delete countdowns, via forged request g...

Affected:
up to 0.6.2
Fix:
No patched version reported
Disclosed:
Dec 23, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database