
CVE-2026-1654 The Peter's Date Countdown plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and incl… https://www.cve.org/CVERecord?id=CVE-2026-1654
Post summary
CVE-2026-1654 exposes reflected XSS in Peter's Date Countdown plugin via the PHP_SELF parameter; no PoC, exploit, or patch details are mentioned.

