Cross-Site Request Forgery Vulnerability in Redirect Countdown Plugin for WordPress
CVE-2026-1390
4.3MEDIUM
What is CVE-2026-1390?
The Redirect Countdown plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the absence of nonce validation in the countdown_settings_content() function. This flaw potentially permits them to manipulate plugin settings such as countdown timeout, redirect URLs, and custom text by deceiving a site administrator into executing a crafted request. As a result, site security can be compromised, making it essential for users to assess and apply necessary countermeasures.
Affected Version(s)
Redirect countdown 0 <= 1.0