← back
CVE-2021-24820CWE-22

Cost Calculator <= 1.6 - Authenticated Local File Inclusion

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.0%
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
nono source reports it
The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout