Input validation vulnerability in Countdown Timer for WordPress Block Editor 1.0.5

The WordPress plugin called Countdown Timer for WordPress Block Editor has a security issue where it is vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This can happen when the plugin’s Countdown widget is used and affects all versions up to and including 1.0.5. The problem is caused by not properly checking and filtering the information that users enter, making it possible for someone with contributor-level access or higher to add harmful code to a webpage.

Detected in:

Countdown Timer for WordPress Block Editor open vulnerable versions: >= * <= 1.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.