CVE 7.2 HIGH

Easy Timer <= 4.2.1 - Authenticated (Editor+) Remote Code Execution via Shortcode_CVE-2025-9519

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This is due to insufficient restriction of shortcode attributes. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

Basic Information

ID CVE-2025-9519
Source Wordfence
Published Sep 4, 2025 at 04:23

Affected Product

Vendor kleor
Product Easy Timer
Version *
Affected Versions kleor Easy Timer *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.