cvemon logocvemon logo

Activity

Trending

CVEs

CVE-2025-26938

Published Feb 25, 2025

Last updated 6 days ago

  1. Overview

  2. Weaknesses

  3. Social media

  4. References

Overview

Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer countdown-time allows Stored XSS.This issue affects Countdown Timer: from n/a through <= 1.2.6.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Weaknesses

audit@patchstack.com
CWE-79

Social media

Hype score
Not currently trending
  1. CVE-2025-26938 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer https://t.co/d6y8rQR1wy

    @VulmonFeeds

    25 Feb 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-26938 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects C… https://t.co/VxQ84v1NIi

    @CVEnew

    25 Feb 2025

    173 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26938
  • https://patchstack.com/database/Wordpress/Plugin/countdown-time/vulnerability/wordpress-countdown-timer-block-plugin-1-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds