CVE-2022-29423 LOW

CVE-2022-29423: WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerability

Vendor Adam Skaat
Product Countdown & Clock (WordPress plugin)
Weakness CWE-264
Published May 6, 2022
Last update April 28, 2026

CVSS base score

3.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Countdown & Clock WordPress plugin through version 2.3.2 contains a vulnerability that allows administrators to read and modify sensitive plugin settings. An attacker with admin-level access can view or alter configuration data, including potentially sensitive options stored in the plugin's settings. This requires existing high-level site access and does not affect site availability.

What an attacker can do

03Attacker Capabilities

Read and modify plugin settings and configuration data with admin-level access.

Potential impact on your site

04Site Impact

Admins should audit plugin settings and ensure only trusted administrators have access to the site.

Conditions required to exploit

05Prerequisites

Attacker must have WordPress administrator privileges on the site.

Key dates

06Disclosure timeline

May 6, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE