Cross-Site Scripting Vulnerability in Uji Countdown Plugin by Patchstack
CVE-2025-52749

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-52749?

The Uji Countdown plugin for WordPress is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of user input during web page generation. This flaw enables malicious actors to inject harmful scripts that can be executed in the browser of users visiting the affected page. An attacker may exploit this vulnerability to gain unauthorized access to sensitive information, manipulate content on the site, or perform actions on behalf of unsuspecting users. Users and administrators are advised to update to the latest version or apply the necessary patches to mitigate this security risk.

Affected Version(s)

Uji Countdown <= n/a

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.