VendorsWow-Companycounter_boxall versions
Vulnerabilities

Wow-Company Counter Box

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-2245
Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF
Published 2022-08-01 · Modified
8.8EPSS 0.005
CVE-2022-29446
WordPress Counter Box plugin <= 1.1.1 - Authenticated Local File Inclusion (LFI) vulnerability
Published 2022-05-19 · Modified
7.2EPSS 0.010
CVE-2023-2362
Multiple Plugins from Wow-Company - Reflected XSS
Published 2023-06-12 · Modified
6.1EPSS 0.005
CVE-2025-24715
WordPress Counter Box Plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Published 2025-01-24 · Modified
5.4EPSS 0.002
CVE-2024-3481
Counter Box < 1.2.4 - Counter Deletion via CSRF
Published 2024-05-02 · Analyzed
5.2EPSS 0.003
CVE-2024-13901
Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site <= 2.0.6 - Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting
Published 2025-03-01 · Analyzed
4.8EPSS 0.003