Flickdevs develops countdown-timer plugins for WordPress and Elementor page-builder environments, with its vulnerability profile centered on cross-site scripting weaknesses in web-facing form and content-handling logic. Treat this as a compact vendor profile focused on application-layer input-neutralization issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flickdevs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13113MEDIUM The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role a | Feb 26, 2025 | 5.9 | 18 | NO | NO |
CVE-2024-10631MEDIUM The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post wher | May 15, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flickdevs.
Media articles that mention a CVE ID that affects a product developed by Flickdevs — matched by CVE ID, not by vendor name.