Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 07 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Wed, 07 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes. | |
| Title | Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T09:56:28.389Z
Reserved: 2026-10-02T07:57:47.460Z
Link: CVE-2026-104667
Updated: 2026-10-07T09:54:50.918Z
Status : Received
Published: 2026-10-07T07:16:58.160
Modified: 2026-10-07T10:17:28.673
Link: CVE-2026-104667
No data.
OpenCVE Enrichment
Updated: 2026-10-07T08:00:12Z