Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Duc Long

#42973of 56,330
6.6Total CVSS
Vulnerabilities · 1
PT-2026-50254
6.6
2026-06-17
WordPress · Counter Box · CVE-2026-12115
**Name of the Vulnerable Software and Affected Versions** The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress versions prior to 2.0.14 **Description** The plugin is susceptible to PHP Object Injection due to the deserialization of untrusted input. This allows authenticated attackers with administrator-level access or higher to inject a PHP Object. Deserialization occurs automatically during the post-import redirect that renders the list table and when an item is opened for editing. While no POP chain (a sequence of gadgets used to achieve code execution during deserialization) is present within the software itself, the presence of a POP chain in another installed plugin or theme could enable attackers to delete arbitrary files, retrieve sensitive data, or execute code. **Recommendations** Update to a version later than 2.0.13.