CVE-2026-83546: Unknown Coolclock

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.

Affected products

  • Unknown Coolclock: before 4.3.8 (fixed in 4.3.8)

Published 2026-09-11. Last modified 2026-09-11.