Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High2
Medium2
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2024-11-21

CVE-2023-4000 - One Click Countdowns Plugin

The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to create and delete countdowns, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN One Click Countdowns

CVE-2023-4000

MEDIUM CVSS 6.3 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-3999 - One Click Countdowns Plugin

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create and delete countdowns as well as manipulate other plugin settings.

PLUGIN One Click Countdowns

CVE-2023-3999

MEDIUM CVSS 6.3 2023-08-31
Threat Entry Updated 2024-11-21

CVE-2023-2757 - One Click Countdowns Plugin

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to access functions to save plugin data that can potentially lead to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN One Click Countdowns

CVE-2023-2757

HIGH CVSS 7.4 2023-05-18
Scroll to top