CVE-2025-49908: WordPress WPC Countdown Timer for WooCommerce plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Countdown Timer for WooCommerce wpc-countdown-timer allows Stored XSS.This issue affects WPC Countdown Timer for WooCommerce: from n/a through <= 3.1.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49908?
CVE-2025-49908 is classified as a high-severity vulnerability due to its potential for exploitation through stored cross-site scripting (XSS).
How do I fix CVE-2025-49908?
To fix CVE-2025-49908, update the WPC Countdown Timer for WooCommerce to the latest version beyond 3.1.4.
What does CVE-2025-49908 affect?
CVE-2025-49908 affects the WPC Countdown Timer for WooCommerce versions from n/a to 3.1.4.
What type of vulnerability is CVE-2025-49908?
CVE-2025-49908 is an improper neutralization of input during web page generation, specifically a Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-49908 lead to data theft?
Yes, CVE-2025-49908 can potentially lead to data theft as it allows attackers to execute malicious scripts in the context of the victim's session.