The Counter Box WordPress plugin prior to 1.2.4 does not have CSRF checks in some bulk actions, which could allow malicious users to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks