Cross-Site Scripting Vulnerability in Uji Countdown Plugin by Patchstack
CVE-2025-52749
What is CVE-2025-52749?
The Uji Countdown plugin for WordPress is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of user input during web page generation. This flaw enables malicious actors to inject harmful scripts that can be executed in the browser of users visiting the affected page. An attacker may exploit this vulnerability to gain unauthorized access to sensitive information, manipulate content on the site, or perform actions on behalf of unsuspecting users. Users and administrators are advised to update to the latest version or apply the necessary patches to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Uji Countdown <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved