CVE-2021-24272

MEDIUM

Codeinitiator Fitness Calculators < 1.9.6 - CSRF

Title source: rule

Description

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

Exploits (1)

exploitdb WORKING POC
by 0xB9 · htmlwebappsphp
https://www.exploit-db.com/exploits/50325

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
codeinitiator/fitness_calculators < 1.9.6
Published May 05, 2021
Tracked Since Feb 18, 2026