PT-2026-6053 · WordPress · Peter’S Date Countdown
Abdulsamad Yusuf
·
Published
2026-02-05
·
Updated
2026-02-05
·
CVE-2026-1654
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Peter's Date Countdown plugin for WordPress versions prior to 2.0.1
Description
The Peter's Date Countdown plugin for WordPress is susceptible to Reflected Cross-Site Scripting. This is due to insufficient input sanitization and output escaping. An unauthenticated attacker can inject arbitrary web scripts into pages, which will execute if a user is tricked into performing an action, such as clicking a link. The vulnerability is related to the
$ SERVER['PHP SELF'] parameter.Recommendations
Update the Peter's Date Countdown plugin to version 2.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peter’S Date Countdown