vulnerability

WordPress Plugin: countdown-wpdevart-extended: CVE-2021-34636: Cross-Site Request Forgery (CSRF)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Sep 27, 2021
Added
May 15, 2025
Modified
Jul 9, 2025

Description

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.

Solution

countdown-wpdevart-extended-plugin-cve-2021-34636
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.