Unauthorized Data Loss in Ninja Countdown Plugin for WordPress
CVE-2025-12665

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 November 2025

What is CVE-2025-12665?

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is prone to a vulnerability that leads to unauthorized data loss. Specifically, this issue arises from a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint, affecting all versions up to and including 1.5.0. As a result, authenticated attackers with Subscriber-level access or higher can exploit this flaw to delete countdowns without proper authorization, potentially compromising the integrity of countdown data within the WordPress site.

Affected Version(s)

Ninja Countdown | Fastest Countdown Builder * <= 1.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Cese
.
CVE-2025-12665 : Unauthorized Data Loss in Ninja Countdown Plugin for WordPress