CVE-2025-24719
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-24719 is a Cross-site Scripting (XSS) vulnerability affecting the Widget Countdown plugin for WordPress. The flaw, which allows Stored XSS attacks, resides in the wpdevart plugin's Web Page Generation process. Attackers can inject malicious scripts into a targeted website by exploiting the improper neutralization of user-supplied input. This issue poses a significant risk, as XSS vulnerabilities enable unauthorized code injection and potentially lead to data theft or site takeover. The flaw impacts versions of Widget Countdown from n/a through 2.7.1, making it essential for users to promptly update to a patched version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.