VYPR

Waiting One Click Countdowns

by WordPress

CVEs (3)

  • CVE-2023-28659HigMar 22, 2023
    risk 0.57cvss 8.8epss 0.01

    The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

  • CVE-2023-2757HigMay 18, 2023
    risk 0.48cvss 7.4epss 0.00

    The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and…

  • CVE-2023-3999MedAug 31, 2023
    risk 0.41cvss 6.3epss 0.00

    The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and…