---
id: CVE-2026-104667
title: >-
  The Animated Number Counters WordPress plugin before 3.1 does not sanitise or
  escape a value stored by an Editor-level user before concatenating it into a
  SQL query that runs when any unauthenticated visitor renders a page containing
  the…
summary: >-
  The Animated Number Counters WordPress plugin before 3.1 does not sanitise or
  escape a value stored by an Editor-level user before concatenating it into a
  SQL query that runs when any unauthenticated visitor renders a page containing
  the…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-89
product: Animated Number Counters
affected:
  - animated_number_counters < 3.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T10:17:28.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104667'
references:
  - url: 'https://wpscan.com/vulnerability/ccaedf47-6a6b-429b-aae9-3b4254181dd9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T09:54:57.715209Z'
ingestedAt: '2026-10-07T08:20:03.939Z'
---

## Overview

The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
