PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2012-0896 Scanner

CVE-2012-0896 scanner - Path Traversal vulnerability in Count Per Day plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2012-0896
5.0
CVSS

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Count Per Day is a very popular plugin for WordPress websites that provides valuable analytics about their visitors' behavior and website traffic. It helps website owners understand how their audience interacts with their content, where they come from, and what they are searching for. Count Per Day's colorful graphs and detailed reports make it easy to monitor website traffic and identify areas for improvement.

However, like any software, Count Per Day is not immune to vulnerabilities. CVE-2012-0896 is one such vulnerability detected in versions of the Count Per Day module prior to 3.1.1. This security flaw is an absolute path traversal vulnerability in download.php, and it allows remote attackers to read any file on a victim's server by exploiting the f parameter.

This vulnerability can lead to severe consequences if left unchecked. An attacker can exploit the vulnerability by downloading sensitive files such as database backups, configuration files, credentials, and other information that can be used to compromise the security of the website or the entire server. In the worst-case scenario, an attacker can gain administrative access to the website, steal data, and affect the integrity of the website and its users.

In conclusion, website security should never be taken lightly. It is always a good idea to be proactive and take precautions to protect digital assets. Thanks to pro features of the s4e.io platform, individuals can easily and quickly identify vulnerabilities in their digital assets and take steps to secure them. By working together, we can keep our websites and data safe from harm.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners and administrators can take several precautions:

  • Update to the latest version of the Count Per Day plugin. The vulnerability has been fixed in version 3.1.1
  • Regularly update the software and plugins used on the website
  • Use security plugins such as WordFence or Sucuri to add an extra layer of protection to the website
  • Harden the server configuration and permissions to prevent unauthorized access
  • Limit the access of untrusted users and prevent them from uploading files or executing arbitrary code on the server

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2012-0896 scanner - Path Traversal vulnerability in Count Per Day plugin for WordPress | S4E