Counter box
This hub aggregates every CVE we track for Counter box, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH1
Monthly trend
0
0
0
0
1
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Counter box.
- CVE-2024-13901Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site <= 2.0.6 - Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting4.4
- CVE-2025-24715WordPress Counter Box Plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability5.4
- CVE-2024-3481Counter Box < 1.2.4 - Counter Deletion via CSRF5.2
- CVE-2023-2362Multiple Plugins from Wow-Company - Reflected XSS6.1
- CVE-2022-2245Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF8.8
- CVE-2022-29446WordPress Counter Box plugin <= 1.1.1 - Authenticated Local File Inclusion (LFI) vulnerability6.8
Product normalization is registry-driven with AI assist and human review. How it works