CVE Database
/

CVE-2021-24821

Back to search

CVE-2021-24821

Published: Mar 7, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a Project (injected on the edit project page)

VendorProductVersions

Unknown

Cost Calculator

affected
1.6 - < 1.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now