CVE-2026-104667: Unknown Animated Number Counters

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.

Affected products

  • Unknown Animated Number Counters: before 3.1 (fixed in 3.1)

Published 2026-10-07. Last modified 2026-10-07.