CVE-2024-10631: Countdown Timer <= 1.0.5 - Contributor+ Stored XSS
The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10631?
CVE-2024-10631 is considered a high severity vulnerability as it allows stored cross-site scripting attacks.
How do I fix CVE-2024-10631?
To fix CVE-2024-10631, update the Countdown Timer for WordPress Block Editor plugin to version 1.0.6 or later.
Who is affected by CVE-2024-10631?
Users with contributor roles and above on WordPress installations using Countdown Timer plugin version 1.0.5 or lower are affected by CVE-2024-10631.
What type of attack can CVE-2024-10631 facilitate?
CVE-2024-10631 can facilitate stored cross-site scripting (XSS) attacks due to improper validation and escaping of block options.
Is there a workaround for CVE-2024-10631?
There is no official workaround for CVE-2024-10631, so updating the plugin is the recommended mitigation.