Peter’s Date Countdown
Peter’s Date Countdown has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Peter’s Date Countdown has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdulsamad Yusuf (0xVenus). Peter’s Date Countdown is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.6.
CVE-2026-1654Peter's Date Countdown <= 2.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
Read the full analysisVulnerability Records
Peter’s Date Countdown
Author
Peter
Display a countdown of important dates. A real-time JavaScript version is also available. The plugin can be used as widget if needed. See the plugin page at https://www.theblog.ca/date-countdown for full information.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C