Edmonsoft develops a small suite of web-page builder and plugin products, primarily countdown and accordion components, where the vulnerability profile centers on client-side input handling and authorization weaknesses typical of dynamic web content. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity, and the recurring exposure in cross-site scripting, missing authorization, and related placeholder issues reflects the interaction-heavy nature of browser-based builder tools. Defenders deploying these plugins should prioritize review of user-generated content sanitization and access control boundaries; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Edmonsoft over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29423CRITICAL Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. | May 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-2017MEDIUM The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and swi | Jun 6, 2024 | 5.4 | 25 | NO | NO |
CVE-2023-3392HIGH The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Objec | Oct 16, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-29421MEDIUM Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type vulnerable parameter. | May 6, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-29422MEDIUM Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock plugin <= 2.3.2 at WordPress via &ycd-countdown-width, &ycd- | May 6, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-29420MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat Countdown & Clock (WordPress plugin) countdown-builder allow | May 6, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-0601MEDIUM The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Refle | Mar 14, 2022 | 6.1 | 18 | NO | NO |
CVE-2024-13639MEDIUM The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all | Feb 13, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Edmonsoft.
Media articles that mention a CVE ID that affects a product developed by Edmonsoft — matched by CVE ID, not by vendor name.