Stored Cross-Site Scripting Vulnerability in HurryTimer for WordPress
CVE-2024-13735
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2025
What is CVE-2024-13735?
The HurryTimer plugin for WordPress, used for creating scarcity and urgency countdown timers, is prone to a Stored Cross-Site Scripting vulnerability. This weakness arises from inadequate sanitization of input and output associated with campaign names. Authenticated users, such as those with Contributor-level access and above, can exploit this flaw to insert arbitrary scripts into pages that are viewed by users. Consequently, this can lead to unauthorized actions and sensitive data exposure if a user accesses an affected page.
Affected Version(s)
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce * <= 2.11.2