wpdevart Vulnerabilities and Affected Products
Vulnerabilities associated with Countdown and CountUp, WooCommerce Sales Timers.
Products
Clear product- Booking calendar, Appointment Booking System12 vulnerabilities
- Responsive Image Gallery, Gallery Album5 vulnerabilities
- Organization chart4 vulnerabilities
- booking_calendar3 vulnerabilities
- Gallery – Image and Video Gallery with Thumbnails3 vulnerabilities
- Contact Form Builder, Contact Widget2 vulnerabilities
- Responsive Vertical Icon Menu2 vulnerabilities
- Widget Countdown2 vulnerabilities
- YouTube Embed, Playlist and Popup by WpDevArt2 vulnerabilities
- Booking Calendar Pro WpDevArt1 vulnerability
- Coming soon and Maintenance mode1 vulnerability
- Contact Form Builder1 vulnerability
- Countdown and CountUp, WooCommerce Sales Timer1 vulnerability
- Countdown and CountUp, WooCommerce Sales Timers1 vulnerability
- Countdown Timer – Widget Countdown1 vulnerability
- Image and Video Lightbox, Image PopUp1 vulnerability
- Poll, Survey, Questionnaire and Voting system1 vulnerability
- Poll, Survey, Questionnaire and Voting system (WordPress plugin)1 vulnerability
- poll\,_survey\,_questionnaire_and_voting_system1 vulnerability
- Pricing Table builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-34636HIGH | Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site ScriptingThe Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7. CWE-352Sep 28, 2021 | CVSS8.8v3.1 | EPSS0.625% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |