Stored Cross-Site Scripting Vulnerability in Widget Countdown by Wpdevart
CVE-2025-47443
What is CVE-2025-47443?
The Widget Countdown plugin by Wpdevart is impacted by a stored Cross-site Scripting (XSS) vulnerability due to improper input neutralization during web page generation. This flaw, present in versions from n/a through 2.7.4, permits attackers to inject malicious scripts. When users interact with the affected product, these scripts can be executed, potentially compromising sensitive information or user accounts. It is crucial for users to apply updates and implement security measures to protect their WordPress sites from exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Widget Countdown <= 2.7.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved