WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Hurrytimer safe?

Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.

What this plugin does

  • Slug: hurrytimer
  • Author: Nabil Lemsieh
  • 20000+ active installs
  • 96/100 rating (169 reviews on wordpress.org)
  • 523428 all-time downloads
  • On WordPress.org since 2018-11-08

countdown timerevergreen countdownflash sale timerrecurring countdown timersales countdown timer

Maintenance status

  • Last updated: 2026-07-10 3:46pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

5 known CVEs on file for Hurrytimer. Reported between 2024 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-24392 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.14.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.14.3 2.14.3 2026-01-11
CVE-2025-53255 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.14.0 Missing Authorization Medium 5.3 < 2.14.0 2.14.0 2025-06-27
CVE-2024-13735 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.12.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.12.0 2.12.0 2025-02-13
CVE-2024-8667 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.11.0 Missing Authorization Medium 4.3 < 2.11.0 2.11.0 2024-10-23
CVE-2024-32556 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce [hurrytimer] < 2.10.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.10.0 2.10.0 2024-04-16

CVE-2026-24392

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-53255

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.13.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Source: Wordfence

CVE-2024-13735

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping of a campaign name. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-8667

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers, with contributor-level access and above, to publish arbitrary posts like ones they have submitted for review, or a site administrator has in draft.

Source: CVE.org

CVE-2024-32556

The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.