Cross-Site Scripting Vulnerability in The Events Calendar Countdown Addon by CoolHappy
CVE-2025-49311
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 June 2025
What is CVE-2025-49311?
The Events Calendar Countdown Addon by CoolHappy is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper input handling during web page generation. This flaw can allow attackers to inject malicious scripts, which may lead to the storage of harmful content on the server, compromising user data and site integrity. Users should ensure they are using the latest version of the addon to mitigate potential security risks.
Affected Version(s)
The Events Calendar Countdown Addon <= 1.4.9