Count Per Day Project maintains a narrowly scoped WordPress plugin focused on post-counting functionality that is distributed within the WordPress ecosystem. The identified vulnerability profile centers on web-application input-handling weaknesses—cross-site scripting, path traversal, and SQL injection—that are characteristic of plugin-level code working within the WordPress environment. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Count Per Day Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0896MEDIUM Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter. | Jan 20, 2012 | 5.0 | 48 | NO | YES |
CVE-2015-5533HIGH SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL comman | Oct 23, 2017 | 7.2 | 30 | NO | YES |
CVE-2012-6714MEDIUM The count-per-day plugin before 3.2.3 for WordPress has XSS via search words. | Aug 21, 2019 | 6.1 | 22 | NO | NO |
CVE-2013-7472MEDIUM The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter. | Jun 15, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Count Per Day Project.
Media articles that mention a CVE ID that affects a product developed by Count Per Day Project — matched by CVE ID, not by vendor name.