CVE Database /
CVE-2024-2017
CVE · Medium
CVE-2024-2017 — Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.7.8.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2017
|
Countdown, Coming Soon, Maintenance – Countdown & Clock [countdown-builder] < 2.7.8.1 |
Missing Authorization |
Medium
5.4
|
< 2.7.8.1
|
2.7.8.1 |
2024-06-05 |
—
|
CVE-2024-2017
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress contains a capability check vulnerability that affects versions up to 2.7.8. Authenticated attackers with subscriber-level permissions or higher can exploit missing security controls in the conditionsRow and switchCountdown functions to inject PHP objects and alter countdown statuses. The vulnerability requires an authenticated account but no elevated privileges, making it accessible to low-level users.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings