WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Widget Countdown safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Widget Countdown WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: widget-countdown
  • 10000+ active installs

countdowncountdown generatorcountdown systemcountdown timercountdown widget

Maintenance status

  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

3 known CVEs on file for Widget Countdown. Reported between 2025 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14555 Countdown Timer – Widget Countdown [widget-countdown] < 2.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.7.8 2.7.8 2026-01-09
CVE-2025-47443 Countdown Timer – Widget Countdown [widget-countdown] < 2.7.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.7.5 2.7.5 2025-05-07
CVE-2025-24719 Countdown Timer – Widget Countdown [widget-countdown] < 2.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.7.2 2.7.2 2025-01-24

CVE-2025-14555

The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdevart_countdown' shortcode in all versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2025-47443

The Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-24719

The Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.