CVE-2026-83546: CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute
Published Sep 11, 2026
·Updated
The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
Affected Software
1 affected component
CoolClock WordPress plugin<4.3.8
Event History
Sep 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with contributor-level access or higher can exploit it. This requires authenticated access to the WordPress site with at least the Contributor role.
2
When does the injected script execute?
The injected script executes when content containing the malicious skin setting is viewed. Users who view that content may be exposed to the script execution.
3
Which plugin versions are affected?
CoolClock versions before 4.3.8 are affected. Updating to version 4.3.8 or later removes the identified vulnerable version range.