Description
WordPress Plugin Count per Day is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Count per Day version 3.2.5 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 3.2.6 or latest
References
http://www.securityfocus.com/bid/58598/exploit
http://www.exploit-db.com/exploits/24859/
http://packetstormsecurity.com/files/120870/WordPress-Count-Per-Day-3.2.5-XSS.html
Related Vulnerabilities
WordPress Plugin N-Media Website Contact Form with File Upload Local File Inclusion (1.5)
WordPress Plugin Local Weather Cross-Site Scripting (1.0)
WordPress Plugin WooCommerce Cross-Seller Unspecified Vulnerability (1.0.2)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-0701)
WordPress Plugin If>So Dynamic Content Unspecified Vulnerability (1.4.1)