CVE-2024-13864

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 11, 2025

Summary

CVE-2024-13864 is a vulnerability affecting the Countdown Timer WordPress plugin. This issue allows an attacker to inject malicious scripts into the plugin due to insufficient sanitization and escaping of user input. As a result, Reflected Cross-Site Scripting attacks can occur, posing a significant risk to high privilege users, such as administrators. Successful exploitation can lead to unauthorized access, data theft, or other malicious activities. Users are advised to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share