CVE-2026-1654 | Peters Date Countdown Plugin up to 2.0.0 on WordPress $_SERVER['PHP_SELF'] cross site scripting
A vulnerability was found in Peters Date Countdown Plugin up to 2.0.0 on WordPress. It has been classified as problematic. Affected is an unknown function. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting.
This vulnerability is known as CVE-2026-1654. Remote exploitation of the attack is possible. No exploit is available.