SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-83545

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The CoolClock WordPress plugin prior to version 4.3.8 is vulnerable to cross-site scripting (XSS) due to improper escaping of a custom skin setting, enabling users with contributor-level access and above to inject malicious JavaScript. This could lead to unauthorized actions or data exposure when the content is viewed by others. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-83545
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress Java

Original NVD Description

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.