WordPress security by component
coolclock
coolclock (coolclock) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.8.
Plugin slug:
coolclockLatest vulnerability
CVE-2026-83546: CoolClock permits contributor stored XSS in HTML attributes
CoolClock before 4.3.8 outputs an attacker-controlled skin setting inside an HTML attribute without adequate escaping. A Contributor or higher role can store script-bearing markup that executes when the affected content is viewed. The authoritative export does not name the setting, save action, or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-83546
CoolClock permits contributor stored XSS in HTML attributes
CoolClock before 4.3.8 outputs an attacker-controlled skin setting inside an HTML attribute without adequate escaping. A Contributor or higher role can store script-bearing markup that executes when the affected content is viewed. The authoritative export does not name the setting, save action, or rendering function.
|
4.3.8 |
CVE6.8
NVDPending
|
| Sep 11, 2026 |
CVE-2026-83545
CoolClock permits contributor stored XSS in inline scripts
CoolClock before 4.3.8 outputs an attacker-controlled custom skin setting inside an inline script without adequate escaping. A Contributor or higher role can store arbitrary JavaScript that executes when the affected content is viewed. The authoritative export does not name the setting, save action, or rendering function.
|
4.3.8 |
CVE6.8
NVDPending
|
| Sep 27, 2021 |
CVE-2021-24670
CoolClock: Cross-site scripting
CoolClock is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|