CVE-2025-47443: WordPress Widget Countdown plugin <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47443?
CVE-2025-47443 is classified as a high-severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
How do I fix CVE-2025-47443?
To fix CVE-2025-47443, update the wpdevart Widget Countdown plugin to version 2.7.5 or later, which addresses this vulnerability.
What is the impact of CVE-2025-47443?
The impact of CVE-2025-47443 allows an attacker to execute arbitrary JavaScript code in the context of other users’ browsers through stored XSS.
Which versions are affected by CVE-2025-47443?
CVE-2025-47443 affects wpdevart Widget Countdown versions up to and including 2.7.4.
Who is primarily affected by CVE-2025-47443?
Users of the wpdevart Widget Countdown plugin on WordPress sites are primarily affected by CVE-2025-47443.