CVE · Medium

CVE-2024-8667 — HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.11.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8667 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.11.0 Missing Authorization Medium 4.3 < 2.11.0 2.11.0 2024-10-23

CVE-2024-8667

The HurryTimer plugin for WordPress and WooCommerce contains a security flaw that allows authorized users with contributor privileges or higher to bypass normal posting restrictions. This vulnerability affects all versions up to 2.10.0, enabling attackers to publish posts they've submitted for review or drafted by site administrators without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.