WP Flipclock

WP Flipclock has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for WP Flipclock has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. WP Flipclock is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all WP Flipclock vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-39540

WP Flipclock <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
WP Flipclock banner
Latestv1.10.1

WP Flipclock

Rhys Wynne

Author

Rhys Wynne

4.0(10)
80/100
Last Updated
2025-12-11 (9mo ago)
Active Installs
600+
Downloads
44,054
Requires WP
3.8.1+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2014-03-16 (13y ago)

WP Flipclock is a plugin that allows you to quickly and easily add a flipclock to your site’s posts and pages via a shortcode. The plugin allows you to count down or up from a specific date, as well as choose whether you count down days, hours or minutes. To use the plugin in your site, all you need to add to the page is the [flipclock] shortcode. There are various attributes you can add as well:- name – Give the flipclock a name. Default is “flipclock”. If you have more than one flipclock on any page it’s useful to give them unique names. countdown (True/False) – Allows you to count down to a date (true), or count up from a date (false). Default is false. date – Any date string, formatted how you like, which the clock will count up from/down to. Default is none. face (days/hours/minutes) – The face of the clock. Default is hours. Options are:- days – Days : Hours : Minutes : Seconds hours – Hours : Minutes : seconds minutes – Minutes : Seconds lang – Changes the language of the labels (days,hours,minutes,seconds). Supported languages: English, Russian, Spanish, French, German. timezone – Sets timezone for date. Now it shows the correct time before the event. The time zones have unique names in the form “Area/Location”, e.g. “America/New_York”. seconds – Hides|shows seconds in face-mode “days”. 1 – shows seconds 0 – hide seconds hidelabel – Adds the ability to hide the labels. This plugin uses the Flipclock.js library from ObjectiveHTML. Further support and examples are on the WP Flipclock Documentation page. About Winwar Media This plugin is made by Winwar Media, a WordPress Development and Training Agency in Manchester, UK. Why don’t you? Check out our book, bbPress Complete Check out our other WordPress Plugins, including WP Email Capture Follow us on Social Media, such as Facebook, Twitter or Google+ Send us an email! We like hearing from plugin users. For Support We offer support in two places:- Support on the WordPress.org Support Board A priority support forum, which offers same-day responses. On Github This project is now on github, you can view the repository here. There are other versions, but this is the one I’ve put up, so where all the developmental will be tracked. Found a Bug? Any bugs found, please contact us.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C