CVE-2026-104667 PUBLISHED

Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.

Product Status

Vendor Unknown
Product Animated Number Counters
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)

Credits

  • Seongwon Lee finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE