Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

WooCommerce Coming Soon Product with Countdown allows Attackers to Inject Malicious Code

CVE-2026-27354
Summary

A security issue in WooCommerce Coming Soon Product with Countdown allows attackers to inject malicious code into the website, potentially stealing user data or taking control of the site. This affects all versions up to 5.0, so it's essential to update to the latest version to fix the issue. If you're using an affected version, we recommend upgrading as soon as possible to protect your site and users.

Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows St...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows Stored XSS.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0.
nvd CVSS3.1 6.5
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026