What the vulnerability does
01Description
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
Explanation of Vulnerability in Simple Terms
Counter Box version 1.1.1 and earlier contains a vulnerability that allows authenticated administrators with high privileges to perform unauthorized actions when a user is tricked into visiting a malicious page. The vulnerability affects data confidentiality, integrity, and availability. Site administrators should update to a version newer than 1.1.1 when available.
What an attacker can do
An authenticated admin can modify or delete site data if a user clicks a malicious link.
Potential impact on your site
An admin account could be compromised to alter or destroy site content and settings.
Conditions required to exploit
Attacker must have admin-level access and the victim must click a link or visit a page.
Key dates
External resources