1 results (0.007 seconds)
CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 1

CVE-2023-0171 – jQuery T(-) Countdown Widget < 2.3.24 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2023-0171
12 Jan 2023 — The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.3.23 due to insufficient input sanitizatio... • https://wpscan.com/vulnerability/32324655-ff91-4a53-a2c5-ebe6678d4a9d • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •