PT-2026-50254 · WordPress · Counter Box

·

CVE-2026-12115

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress versions prior to 2.0.14
Description The plugin is susceptible to PHP Object Injection due to the deserialization of untrusted input. This allows authenticated attackers with administrator-level access or higher to inject a PHP Object. Deserialization occurs automatically during the post-import redirect that renders the list table and when an item is opened for editing. While no POP chain (a sequence of gadgets used to achieve code execution during deserialization) is present within the software itself, the presence of a POP chain in another installed plugin or theme could enable attackers to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations Update to a version later than 2.0.13.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12115

Affected Products

Counter Box