CVE-2025-26938: WordPress Countdown Timer block plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer countdown-time allows Stored XSS.This issue affects Countdown Timer: from n/a through <= 1.2.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26938?
CVE-2025-26938 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-26938?
To fix CVE-2025-26938, update the bPlugins Countdown Timer plugin to a version later than 1.2.6.
What kind of vulnerability is CVE-2025-26938?
CVE-2025-26938 is an improper neutralization of input vulnerability that allows for stored cross-site scripting (XSS).
What software is affected by CVE-2025-26938?
CVE-2025-26938 affects bPlugins Countdown Timer versions from n/a through 1.2.6.
How can CVE-2025-26938 be exploited?
CVE-2025-26938 can be exploited by injecting malicious scripts that are then stored and executed in user browsers.