CVE-2021-24820 β€” Path Traversal in Cost Calculator

CWE-22 β€” Path Traversal3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 25.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28
Latest updateMar 1

Description

The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

πŸ”΄Vulnerability Details

2
GHSA
GHSA-7pg3-r4wv-7xmh: The Cost Calculator WordPress plugin through 1β†—2022-03-01
β–Ά
CVEList
Cost Calculator <= 1.6 - Authenticated Local File Inclusion↗2022-02-28
β–Ά
CVE-2021-24820 β€” Path Traversal in Cost Calculator | cvebase