{"id":"CVE-2026-83545","title":"The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …","summary":"The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79"],"product":"CoolClock","affected":["CoolClock < 4.3.8"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T17:35:21.440","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-83545","references":[{"url":"https://wpscan.com/vulnerability/d331d834-08f7-46e2-859a-7b797213ad0b/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T10:04:21.489220Z"},"epss":0.00235,"epssPercentile":0.14787,"ingestedAt":"2026-09-11T16:45:47.924Z","slug":"CVE-2026-83545","body":"## Overview\n\nThe CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}