CVE-2026-27052
WordPress Sales Countdown Timer for WooCommerce and WordPress plugin < 1.1.9 - Local File Inclusion vulnerability
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
35th
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through < 1.1.9.
| CWE | CWE-98 |
| Vendor | villatheme |
| Product | sales countdown timer for woocommerce and wordpress |
| Published | Feb 19, 2026 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for villatheme sales countdown timer for woocommerce and wordpress
Be the first to know when new high vulnerabilities affecting villatheme sales countdown timer for woocommerce and wordpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
villatheme / Sales Countdown Timer for WooCommerce and WordPress
0 โค 1.1.9
References
Credits
Phat RiO | Patchstack Bug Bounty Program