DOM-Based Stored Cross-Site Scripting in Counter Box Plugin for WordPress
CVE-2024-13901
4.4MEDIUM
Key Information:
- Vendor
- WPcalc
- Status
- Counter Box: Add Engaging Countdowns, Timers & Counters To Your WordPress Site
- Vendor
- CVE Published:
- 1 March 2025
Summary
The Counter Box plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting through the 'content' parameter due to inadequate input sanitization and output escaping. This vulnerability permits authenticated attackers with administrator privileges to inject arbitrary scripts into web pages, which will execute whenever a user accesses the manipulated page. Notably, this issue is present in multi-site installations and in cases where the unfiltered_html capability is disabled.
Affected Version(s)
Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site * <= 2.0.6
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Khanh Hao