Junglewise Threat Intelligence

CVE-2026-83546: CoolClock WordPress plugin stored XSS in skin setting

CVE-2026-83546 · Severity: medium · CVSS 6.8 · Published 2026-09-11

Executive brief

CoolClock is a popular WordPress plugin that adds clock display functionality to website content. A vulnerability in versions before 4.3.8 allows contributors and higher-level users to inject malicious scripts into the plugin's skin setting, which execute in the browsers of anyone viewing the affected content—including site administrators. This could lead to account compromise or malicious actions performed on behalf of users viewing the page.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the CoolClock WordPress plugin caused by improper escaping of the skin parameter before outputting it within an HTML attribute. An authenticated attacker with contributor-level access or higher can craft a malicious shortcode with an unescaped skin value containing JavaScript, which is stored in the post content and executed when the page is rendered. The vulnerability requires authentication but is trivially exploitable through the block editor; no user interaction beyond viewing the page is needed. Attackers can execute arbitrary JavaScript in the context of the site, potentially stealing session tokens, performing unauthorized actions, or defacing content. The vulnerability was fixed in version 4.3.8.

Affected products

  • CoolClock CoolClock before 4.3.8

Timeline

  • 2026-09-08: disclosed: Publicly published
  • 2026-09-11: patched: Fixed in version 4.3.8

References

Related threats