Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-24904. PoCs published by Ceylan BOZOĞULLARINDAN.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in the WordPress Mortgage Calculators WP plugin version 1.52. The exploit involves injecting malicious JavaScript via the background color input field in the admin panel, which executes when visitors view the calculator page.
Description
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in the WordPress Mortgage Calculators WP plugin version 1.52. The exploit involves injecting malicious JavaScript via the background color input field in the admin panel, which executes when visitors view the calculator page.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N