nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24904 CVE-2021-24904
MEDIUM
Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
Record summary
CVE-2021-24904 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Mortgage Calculators WP | CVE List | 1.56 to < 1.56 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)ExploitDB exploitby Ceylan BOZOĞULLARINDANNot analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/7b80f89b-e724-41c5-aa03-21d1eef50f21