kleor Vulnerabilities and Affected Products
Vulnerabilities associated with Easy Timer.
Products
Clear product- Contact Manager4 vulnerabilities
- Easy Timer1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-9519HIGH | Easy Timer <= 4.2.1 - Authenticated (Editor+) Remote Code Execution via ShortcodeThe Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This is due to insufficient restriction of shortcode attributes. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server. CWE-94Sep 4, 2025 | CVSS7.2v3.1 | EPSS0.905% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |