Description
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
Published: 2026-10-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Now
AI Analysis

Impact

The vulnerability arises because the Animated Number Counters WordPress plugin before version 3.1 fails to sanitize or escape an input value entered by an Editor-level user before incorporating it into a SQL query. This second‑order SQL injection allows an unauthenticated visitor to trigger the query when rendering a page that contains the counter, enabling the attacker to read arbitrary database contents, including password hashes. The weakness is a classic SQL injection flaw, thereby compromising the confidentiality of stored data.

Affected Systems

WordPress sites that use the Animated Number Counters plugin with any version earlier than 3.1 are affected. This includes any installation where Editor users have the ability to store counter configuration values that are later used in a database query without proper escaping.

Risk and Exploitability

The attack vector is usable from an unauthenticated web request, implying that any public-facing page rendering the counter can be exploited. The vulnerability would provide an attacker with the ability to read arbitrary data, including user credentials, and therefore poses a high confidentiality risk. However, the CVE record does not disclose a CVSS score, so the severity dimension cannot be quantified here. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the possibility of sensitive data exfiltration warrants immediate attention.

Generated by OpenCVE AI on October 7, 2026 at 07:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Animated Number Counters plugin to version 3.1 or later.
  • Restrict Editor users from creating or modifying counter configurations that are incorporated into SQL queries.
  • If an immediate update is not possible, disable or remove the plugin from the site to eliminate the vulnerability.
  • Ensure that any remaining counter functionality is confined to authenticated or restricted environments and that user input is properly validated and escaped.

Generated by OpenCVE AI on October 7, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
Title Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T09:56:28.389Z

Reserved: 2026-10-02T07:57:47.460Z

Link: CVE-2026-104667

cve-icon Vulnrichment

Updated: 2026-10-07T09:54:50.918Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:58.160

Modified: 2026-10-07T10:17:28.673

Link: CVE-2026-104667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:00:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')