
CVE-2025-24715 – WordPress Counter Box Plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
https://notcve.org/view.php?id=CVE-2025-24715
24 Jan 2025 — Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box allows Cross Site Request Forgery. This issue affects Counter Box: from n/a through 2.0.5. The Counter Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into... • https://patchstack.com/database/wordpress/plugin/counter-box/vulnerability/wordpress-counter-box-plugin-2-0-5-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2024-3481 – Counter Box < 1.2.4 - Counter Deletion via CSRF
https://notcve.org/view.php?id=CVE-2024-3481
11 Apr 2024 — The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks El complemento Counter Box de WordPress anterior a 1.2.4 no tiene comprobaciones CSRF en algunas acciones masivas, lo que podría permitir a los atacantes hacer que los administradores que han iniciado sesión realicen acciones no deseadas, como eliminar contadores mediante ataques CSRF. The Counter ... • https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2023-2362 – Multiple Plugins from Wow-Company - Reflected XSS
https://notcve.org/view.php?id=CVE-2023-2362
22 May 2023 — The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder ... • https://wpscan.com/vulnerability/27e70507-fd68-4915-88cf-0b96ed55208e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-2245 – Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF
https://notcve.org/view.php?id=CVE-2022-2245
08 Jul 2022 — The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks El plugin Counter Box de WordPress versiones anteriores a 1.2.1, carece de una comprobación de tipo CSRF cuando son activados y desactivados los contadores, lo que podría permitir a atacantes hacer que un administrador conectado lleve a cabo tales acciones por medio de ataques de tipo CSRF • https://wpscan.com/vulnerability/33705003-1f82-4b0c-9b4b-d4de75da309c • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-29446 – WordPress Counter Box plugin <= 1.1.1 - Authenticated Local File Inclusion (LFI) vulnerability
https://notcve.org/view.php?id=CVE-2022-29446
16 May 2022 — Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress. Una vulnerabilidad de Inclusión de Archivos Locales (LFI) autenticado (rol de administrador o superior) en el plugin Counter Box de Wow-Company versiones anteriores a 1.1.1 incluyéndola, en WordPress • https://patchstack.com/database/vulnerability/counter-box/wordpress-counter-box-plugin-1-1-1-authenticated-local-file-inclusion-lfi-vulnerability • CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') CWE-552: Files or Directories Accessible to External Parties •