CVE-2026-104667: Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Editor-level access to store a malicious counter order value. The injected SQL is triggered later when an unauthenticated visitor renders a page containing that counter.
Are public-facing pages affected?
Yes. Any page containing the affected counter can trigger the stored payload when it is viewed by an unauthenticated visitor, so exploitation does not require the viewer to be logged in.
What data could be exposed?
The SQL injection can read arbitrary data from the database, including password hashes.