PatchSiren

CoolClock CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CoolClock CVE published 2026-09-11

CVE-2026-83546

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. This vulnerability requires defenders to assess exposure and prioritize verification and updates for WordPress installations with the CoolClock plugi [truncated]

MEDIUM CoolClock CVE published 2026-09-11

CVE-2026-83545

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed. This vulnerability could lead to potential JavaScript injection attacks, arbitrary code execution on affected systems, and possible data theft [truncated]