Impact
The vulnerability arises because the Animated Number Counters WordPress plugin before version 3.1 fails to sanitize or escape an input value entered by an Editor-level user before incorporating it into a SQL query. This second‑order SQL injection allows an unauthenticated visitor to trigger the query when rendering a page that contains the counter, enabling the attacker to read arbitrary database contents, including password hashes. The weakness is a classic SQL injection flaw, thereby compromising the confidentiality of stored data.
Affected Systems
WordPress sites that use the Animated Number Counters plugin with any version earlier than 3.1 are affected. This includes any installation where Editor users have the ability to store counter configuration values that are later used in a database query without proper escaping.
Risk and Exploitability
The attack vector is usable from an unauthenticated web request, implying that any public-facing page rendering the counter can be exploited. The vulnerability would provide an attacker with the ability to read arbitrary data, including user credentials, and therefore poses a high confidentiality risk. However, the CVE record does not disclose a CVSS score, so the severity dimension cannot be quantified here. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the possibility of sensitive data exfiltration warrants immediate attention.
OpenCVE Enrichment