Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.1%
from disclosure to weapon0 days
Published on NVDFeb 14
1st PoCJan 27
exploitation probability
5.1%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected products
Unknown · Mortgage Calculators WPpublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/50685unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.