Plugin Vulnerability Hub
Plugin 10 known issues Latest disclosed Apr 03, 2025

Countdown, Coming Soon, Maintenance – Countdown & Clock Vulnerabilities

Review known vulnerability records for the WordPress plugin Countdown, Coming Soon, Maintenance – Countdown & Clock (`countdown-builder`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-2270, CVE-2025-30841 and CVE-2024-50516, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
10
High or Critical
2
Patch Coverage
100%
Last Updated
May 05, 2025
Priority CVE Quick Links

Fast paths into Countdown, Coming Soon, Maintenance – Countdown & Clock CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
9
CVE-2025-30841 High 2.8.9
CVE-2025-30841 Countdown, Coming Soon, Maintenance – Countdown & Clock Remote Code Execution

Countdown & Clock <= 2.8.8 - Authenticated (Contributor+) Remote Code Execution

CVE-2025-2270 High 2.9.0
CVE-2025-2270 Countdown, Coming Soon, Maintenance – Countdown & Clock Local File Inclusion

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion

CVE-2022-29421 Medium 2.3.3
CVE-2022-29421 Countdown, Coming Soon, Maintenance – Countdown & Clock Cross-Site Scripting

Countdown & Clock <= 2.3.2 - Reflected Cross-Site Scripting

CVE-2022-0601 Medium 2.2.9
CVE-2022-0601 Countdown, Coming Soon, Maintenance – Countdown & Clock Cross-Site Scripting

Countdown & Clock <= 2.2.8 - Reflected Cross-Site Scripting

CVE-2022-29420 Medium 2.3.3
CVE-2022-29420 Countdown, Coming Soon, Maintenance – Countdown & Clock Stored Cross-Site Scripting

Countdown & Clock <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2024-2017 Medium 2.7.8.1
CVE-2024-2017 Countdown, Coming Soon, Maintenance – Countdown & Clock Vulnerability

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection

CVE-2022-29422 Medium 2.3.3
CVE-2022-29422 Countdown, Coming Soon, Maintenance – Countdown & Clock Cross-Site Scripting

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.2 - Cross-Site Scripting

CVE-2024-50516 Medium No patch listed
CVE-2024-50516 Countdown, Coming Soon, Maintenance – Countdown & Clock Stored Cross-Site Scripting

Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Countdown, Coming Soon, Maintenance – Countdown & Clock so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
10 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2025-2270, CVE-2025-30841 and CVE-2024-50516
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Countdown, Coming Soon, Maintenance – Countdown & Clock

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2025-2270
CVE-2025-2270: Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files wit...

Published
Apr 03, 2025
Patched Release
2.9.0
Affected Versions
Versions up to 2.8.9.1
Next Step
Update to 2.9.0 or newer if supported.
Plugin High Patched: Yes CVE-2025-30841
CVE-2025-30841: Countdown & Clock <= 2.8.8 - Authenticated (Contributor+) Remote Code Execution

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the...

Published
Apr 01, 2025
Patched Release
2.8.9
Affected Versions
Versions up to 2.8.8
Next Step
Update to 2.8.9 or newer if supported.
Plugin Medium Patched: No CVE-2024-50516
CVE-2024-50516: Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.3 due to insufficient input sanitization and output escaping. This makes it possible for auth...

Published
Oct 28, 2024
Patched Release
Not published
Affected Versions
Versions up to 2.9.3
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2024-2017
CVE-2024-2017: Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authe...

Published
Jun 05, 2024
Patched Release
2.7.8.1
Affected Versions
Versions up to 2.7.8
Next Step
Update to 2.7.8.1 or newer if supported.
Plugin Medium Patched: Yes
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.9.5 - Authenticated Cross-Site Scripting

The plugin Countdown, Coming Soon, Maintenance – Countdown & Clock for WordPress is vulnerable to Stored Cross-Site Scripting. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Published
May 25, 2022
Patched Release
2.3.9.6
Affected Versions
Versions up to 2.3.9.5
Next Step
Update to 2.3.9.6 or newer if supported.
Plugin Low Patched: Yes CVE-2022-29423
CVE-2022-29423: Countdown & Clock <= 2.3.2 - Pro Features Lock Bypass

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin

Published
Apr 28, 2022
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-29422
CVE-2022-29422: Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.2 - Cross-Site Scripting

Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin

Published
Apr 28, 2022
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-29421
CVE-2022-29421: Countdown & Clock <= 2.3.2 - Reflected Cross-Site Scripting

Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter.

Published
Apr 28, 2022
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-29420
CVE-2022-29420: Countdown & Clock <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin

Published
Apr 28, 2022
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0601
CVE-2022-0601: Countdown & Clock <= 2.2.8 - Reflected Cross-Site Scripting

The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

Published
Feb 21, 2022
Patched Release
2.2.9
Affected Versions
Versions before 2.2.9
Next Step
Update to 2.2.9 or newer if supported.