CVE-2025-9519 | kleor Easy Timer Plugin up to 4.2.1 on WordPress Shortcode code injection
A vulnerability, which was classified as critical, was found in kleor Easy Timer Plugin up to 4.2.1 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. Executing manipulation can lead to code injection.
This vulnerability is registered as CVE-2025-9519. It is possible to launch the attack remotely. No exploit is available.