Stored Cross-Site Scripting Vulnerability in HurryTimer for WordPress
CVE-2024-13735
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2025
What is CVE-2024-13735?
The HurryTimer plugin for WordPress, used for creating scarcity and urgency countdown timers, is prone to a Stored Cross-Site Scripting vulnerability. This weakness arises from inadequate sanitization of input and output associated with campaign names. Authenticated users, such as those with Contributor-level access and above, can exploit this flaw to insert arbitrary scripts into pages that are viewed by users. Consequently, this can lead to unauthorized actions and sensitive data exposure if a user accesses an affected page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HurryTimer β An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce * <= 2.11.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved