plugin

Count Per Day Vulnerabilities

34 known security issues reported for the Count Per Day WordPress plugin. Most recent disclosed Aug 21, 2019.

1 critical 5 high 4 medium

Running Count Per Day on your site? Check whether your installed version is affected.

Scan your site free

Count per Day [count-per-day] < 3.2.3 (closed)

unknown

[en] The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Aug 21, 2019

CVE-2012-6714 on NVD →

Count per Day [count-per-day] < 3.2.6 (closed)

unknown

[en] The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Jun 15, 2019

CVE-2013-7472 on NVD →

Count per Day [count-per-day] < 3.4.1 (closed)

unknown

[en] SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers...

Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Oct 23, 2017

CVE-2015-5533 on NVD →

Count per Day [count-per-day] < 3.5.5 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 12, 2016

Count per Day [count-per-day] < 3.2.4 (closed)

unknown

This plugin is prone to multiple script direct request path disclosure vulnerability. Update the plugin.

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Aug 12, 2016

Count per Day [count-per-day] < 3.2.6 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in "daytoshow" parameter. Update the plugin.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Aug 12, 2016

Count per Day < 3.5.5 - Unauthenticated Stored Cross-Site Scripting

high

The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
8.3
Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 5, 2016

Count per Day [count-per-day] < 3.5.5

unknown

The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 5, 2016

Count per Day < 3.5.5 - Reflected Cross-Site Scripting

high

The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
7.1
Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 4, 2016

Count per Day [count-per-day] < 3.5.5

unknown

The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can...

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Aug 4, 2016

Count per Day [count-per-day] < 3.5.5 (closed)

unknown

Count per Day Plugin before 3.5.4 is prone to a Cross-Site scripting vulnerability. This vulnerability allows remote attackers to perform a number of arbitrary actions. You can exploit it by manipulating the referer header and putting in JavaScript. This security issue was fixed in Count per Day version 3.5.5. Update t...

Affected:
up to 3.5.5
Fixed in:
3.5.5
Disclosed:
Jul 17, 2016

Count per Day <= 3.4 - Cross-Site Request Forgery

high

SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to ex...

CVSS:
7.2
Affected:
up to 3.4.1
Fixed in:
3.4.1
Disclosed:
Jul 22, 2015

CVE-2015-5533 on NVD →

Count Per Day <= 3.2.3 - Path Disclosure and Denial of Service

critical

The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and including, 3.2.3 via the 'notes.php' file. This makes it possible for unauthenticated attackers to disclose sensitive information and slow/deny the responsiveness of the vulnerable service.

CVSS:
9.1
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
Aug 1, 2014

Count per Day < 3.2.6 - Reflected Cross-Site Scripting

high

The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in versions before 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
7.1
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Aug 1, 2014

Count per Day <= 3.1 - Cross-Site Scripting

medium

The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘map’ parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...

CVSS:
6.1
Affected:
up to 3.1
Fixed in:
3.1.1
Disclosed:
Aug 1, 2014

CVE-2012-0895 on NVD →

Count Per Day <= 3.1.1 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.

CVSS:
6.1
Affected:
up to 3.1.1
Fixed in:
3.2
Disclosed:
Aug 1, 2014

CVE-2012-3434 on NVD →

Count per Day [count-per-day] < 3.2.4 (closed)

unknown

The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and including, 3.2.3 via the 'notes.php' file. This makes it possible for unauthenticated attackers to disclose sensitive information and slow/deny the responsiveness of the vulnerable service.

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Aug 1, 2014

Count per Day [count-per-day] < 3.2.6

unknown

The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in versions before 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Aug 1, 2014

Count per Day [count-per-day] < 3.2.6 (closed)

unknown

WordPress Count per Day plugin is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials....

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Mar 19, 2013

Count per Day < 3.2.6 - Cross-Site Scripting

medium

The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.

CVSS:
6.1
Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Mar 5, 2013

CVE-2013-7472 on NVD →

Count per Day [count-per-day] < 3.2.6 (closed)

unknown

WordPress Count Per Day plugin's "daytoshow" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authe...

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Mar 5, 2013

Count per Day [count-per-day] < 3.2.4 (closed)

unknown

WordPress Count per Day plugin is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials....

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
Aug 27, 2012

Count per Day [count-per-day] < 3.2 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.

Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Aug 15, 2012

CVE-2012-3434 on NVD →

Count per Day Plugin < 3.2.3 - Cross-Site Scripting

medium

The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.

CVSS:
6.1
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Jul 20, 2012

CVE-2012-6714 on NVD →

Count per Day [count-per-day] < 3.1.1 (closed)

unknown

[en] Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Jan 20, 2012

CVE-2012-0896 on NVD →

Count per Day [count-per-day] < 3.1.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Jan 20, 2012

CVE-2012-0895 on NVD →

Count per Day <= 3.1 - Arbitrary File Download

high

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

CVSS:
7.5
Affected:
up to 3.1
Fixed in:
3.1.1
Disclosed:
Jan 12, 2012

CVE-2012-0896 on NVD →

Count per Day [count-per-day] < 2.18 (closed)

unknown

Count per Day plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 2.18
Fixed in:
2.18
Disclosed:
Sep 18, 2011

Count per Day [count-per-day] < 3.5.5 (closed)

unknown

The Count per Day WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.5.5
Fixed in:
3.5.5

Count per Day [count-per-day] < 3.5.5 (closed)

unknown

The Count per Day WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.5.5
Fixed in:
3.5.5

Count per Day [count-per-day] < 3.0 (closed)

unknown

The Count per Day WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 3.0
Fixed in:
3.0

Count per Day [count-per-day] < 3.2.4 (closed)

unknown

The Count per Day WordPress plugin was affected by a Multiple Script Direct Request Path Disclosure security vulnerability.

Affected:
up to 3.2.4
Fixed in:
3.2.4

Count per Day [count-per-day] < 3.2.6 (closed)

unknown

The Count per Day WordPress plugin was affected by a counter.php HTTP Referer Header XSS security vulnerability.

Affected:
up to 3.2.6
Fixed in:
3.2.6

Count per Day [count-per-day] < 3.1.1 (closed)

unknown

The Count per Day WordPress plugin was affected by a map.php map Parameter XSS security vulnerability.

Affected:
up to 3.1.1
Fixed in:
3.1.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database