PHP Object Injection Vulnerability in Counter Box Plugin for WordPress
CVE-2026-12115

6.6MEDIUM

What is CVE-2026-12115?

The Counter Box plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted input. This vulnerability affects all versions up to and including 2.0.13. Authenticated attackers with administrator-level access can exploit this flaw to inject PHP Objects. While no known payload chains exist in the vulnerable version, if other themes or plugins with such chains are present, attackers could potentially delete files, access sensitive data, or execute arbitrary code. Deserialization occurs automatically during specific interactions within the plugin, requiring no additional navigation beyond the import process.

Affected Version(s)

Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress 0 <= 2.0.13

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Duc Long
.