PHP Object Injection Vulnerability in Counter Box Plugin for WordPress
CVE-2026-12115
6.6MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 June 2026
What is CVE-2026-12115?
The Counter Box plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted input. This vulnerability affects all versions up to and including 2.0.13. Authenticated attackers with administrator-level access can exploit this flaw to inject PHP Objects. While no known payload chains exist in the vulnerable version, if other themes or plugins with such chains are present, attackers could potentially delete files, access sensitive data, or execute arbitrary code. Deserialization occurs automatically during specific interactions within the plugin, requiring no additional navigation beyond the import process.
Affected Version(s)
Counter Box β Add Countdowns, Timers & Dynamic Counters to WordPress 0 <= 2.0.13