What the vulnerability does
01Description
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
Explanation of Vulnerability in Simple Terms
The Countdown & Clock WordPress plugin through version 2.3.2 contains a vulnerability that allows administrators to read and modify sensitive plugin settings. An attacker with admin-level access can view or alter configuration data, including potentially sensitive options stored in the plugin's settings. This requires existing high-level site access and does not affect site availability.
What an attacker can do
Read and modify plugin settings and configuration data with admin-level access.
Potential impact on your site
Admins should audit plugin settings and ensure only trusted administrators have access to the site.
Conditions required to exploit
Attacker must have WordPress administrator privileges on the site.
Key dates
External resources
Related vulnerabilities