PT-2026-50254 · WordPress · Counter Box
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress versions prior to 2.0.14
Description
The plugin is susceptible to PHP Object Injection due to the deserialization of untrusted input. This allows authenticated attackers with administrator-level access or higher to inject a PHP Object. Deserialization occurs automatically during the post-import redirect that renders the list table and when an item is opened for editing. While no POP chain (a sequence of gadgets used to achieve code execution during deserialization) is present within the software itself, the presence of a POP chain in another installed plugin or theme could enable attackers to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations
Update to a version later than 2.0.13.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Counter Box