Extension WordPress
Vulnérabilités Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress
Cette page rassemble les failles publiées pour Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress
8 fiches
Counter Box <= 2.0.13 – Authenticated (Administrator+) PHP Object Injection via Import
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it…
*-2.0.13
2.0.14
16/06/2026
Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site <= 2.0.6 – Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting
The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 2.0.6 due to insufficient…
*-2.0.6
2.0.7
28/02/2025
Counter Box <= 2.0.5 – Cross-Site Request Forgery
The Counter Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-2.0.5
2.0.6
24/01/2025
Counter Box – WordPress plugin for countdown, timer, counter <= 1.2.3 – Cross-Site Request Forgery
The Counter Box – WordPress plugin for countdown, timer, counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the…
*-1.2.3
1.2.4
11/04/2024
Multiple Wow-Company Plugins (Various Versions) — Reflected Cross-Site Scripting via 'page' parameter
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-1.2.1
1.2.2
22/05/2023
Counter Box – WordPress plugin for countdown, timer, counter <= 1.2 – SQL Injection
The Counter Box plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘s’ parameter in versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-1.2
1.2.1
08/07/2022
Counter Box <= 1.2 – Cross-Site Request Forgery
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
*-1.2
1.2.1
08/07/2022
Counter Box <= 1.1.1 – Authenticated Local File Inclusion
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin
*-1.1.1
1.2
16/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.