CVE-2026-104667: Unknown Animated Number Counters
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
Affected products
- Unknown Animated Number Counters: before 3.1 (fixed in 3.1)
Published 2026-10-07. Last modified 2026-10-07.