← back
CVE-2021-24904CWE-79

Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 5.1%
from disclosure to weapon0 days
Published on NVDFeb 14
1st PoCJan 27
exploitation probability
5.1%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.