Count per Day [count-per-day] < 3.2.3 (closed)
unknown[en] The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.3
- Disclosed:
- Aug 21, 2019
plugin
34 known security issues reported for the Count Per Day WordPress plugin. Most recent disclosed Aug 21, 2019.
Running Count Per Day on your site? Check whether your installed version is affected.
Scan your site free[en] The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
[en] The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
[en] SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers...
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
This plugin is prone to multiple script direct request path disclosure vulnerability. Update the plugin.
This plugin is prone to a cross site scripting vulnerability in "daytoshow" parameter. Update the plugin.
The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
The Count per Day plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can...
The Count per Day plugin for WordPress is vulnerable to Cross-Site Scripting via the 'limit' parameter in versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can...
Count per Day Plugin before 3.5.4 is prone to a Cross-Site scripting vulnerability. This vulnerability allows remote attackers to perform a number of arbitrary actions. You can exploit it by manipulating the referer header and putting in JavaScript. This security issue was fixed in Count per Day version 3.5.5. Update t...
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to ex...
The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and including, 3.2.3 via the 'notes.php' file. This makes it possible for unauthenticated attackers to disclose sensitive information and slow/deny the responsiveness of the vulnerable service.
The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in versions before 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘map’ parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if t...
Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.
The Count Per Day plugin for WordPress is vulnerable to Path Disclosure and Denial of Service in versions up to, and including, 3.2.3 via the 'notes.php' file. This makes it possible for unauthenticated attackers to disclose sensitive information and slow/deny the responsiveness of the vulnerable service.
The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in versions before 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
WordPress Count per Day plugin is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials....
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
WordPress Count Per Day plugin's "daytoshow" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authe...
WordPress Count per Day plugin is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials....
[en] Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
[en] Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
[en] Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
Count per Day plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.
The Count per Day WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.
The Count per Day WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
The Count per Day WordPress plugin was affected by a SQL Injection security vulnerability.
The Count per Day WordPress plugin was affected by a Multiple Script Direct Request Path Disclosure security vulnerability.
The Count per Day WordPress plugin was affected by a counter.php HTTP Referer Header XSS security vulnerability.
The Count per Day WordPress plugin was affected by a map.php map Parameter XSS security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free