CVE-2026-83545: Unknown Coolclock
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.
Affected products
- Unknown Coolclock: before 4.3.8 (fixed in 4.3.8)
Published 2026-09-11. Last modified 2026-09-11.