{"id":"CVE-2026-104667","title":"The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the…","summary":"The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"product":"Animated Number Counters","affected":["animated_number_counters < 3.1"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T10:17:28.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104667","references":[{"url":"https://wpscan.com/vulnerability/ccaedf47-6a6b-429b-aae9-3b4254181dd9/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T09:54:57.715209Z"},"ingestedAt":"2026-10-07T08:20:03.939Z","slug":"CVE-2026-104667","body":"## Overview\n\nThe Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217381,"id":"CVE-2026-104667","ts":1791368785147,"field":"cvss","old":null,"new":"6.8"},{"seq":217380,"id":"CVE-2026-104667","ts":1791368785147,"field":"severity","old":"none","new":"medium"}]}