RSS   Vulnerabilities for 'Mortgage calculators wp'   RSS

2022-02-14
 
CVE-2021-24904

CWE-79
 

 
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

 


Copyright 2024, cxsecurity.com

 

Back to Top