CVE-2026-83546 PUBLISHED

CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute

Assigner: WPScan
Reserved: 31.08.2026 Published: 11.09.2026 Updated: 11.09.2026

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.

Product Status

Vendor Unknown
Product CoolClock
Versions Default: unaffected
  • affected from 0 to 4.3.8 (excl.)

Credits

  • Philipp Doblhofer finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE