CVE-2025-23891 Information

Description

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Vincent Loy Yet Another Countdown allows DOM-Based XSS.This issue affects Yet Another Countdown: from n/a through 1.0.1.

Reference

https://patchstack.com/database/wordpress/plugin/yacp/vulnerability/wordpress-yet-another-countdown-plugin-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve

Share on: