- Description
- The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Source
- security@wordfence.com
- NVD status
- Analyzed
- Products
- counter_box
CVSS 3.1
- Type
- Primary
- Base score
- 4.8
- Impact score
- 2.7
- Exploitability score
- 1.7
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- security@wordfence.com
- CWE-79
- Hype score
- Not currently trending
🚨 CVE-2024-13901 🟠 MEDIUM (4.4) 🏢 wpcalc - Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site 🏗️ * 🔗 https://t.co/PH9qySSyJl 🔗 https://t.co/4GMcZEpmSA 🔗 https://t.co/lxxofgm5M3 #CyberCron #VulnAlert #InfoSec https://t.co/ECJlfeG1Cz
@cybercronai
2 Mar 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-13901 The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the… https://t.co/SquY3tDXXr
@CVEnew
1 Mar 2025
117 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-13901 DOM-Based Stored XSS in Counter Box WordPress Plugin via 'content... https://t.co/DO5LEDD6Yv Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x
@VulmonFeeds
1 Mar 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wow-company:counter_box:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "556A93DC-6E7A-4410-B2DD-70A78DF7933F",
"versionEndExcluding": "2.0.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]