WordPress Plugin Vulnerabilities

Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order

Description

The plugin does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Seongwon Lee
Submitter
Seongwon Lee
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 3 days ago)
Added
2026-10-05 (about 2 days ago)
Last Updated
2026-10-05 (about 2 days ago)

Other