Nicdark Cost Calculator vulnerabilities
3 known vulnerabilities affecting nicdark/cost_calculator.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-0165MEDIUMCVSS 5.4≤ 1.82023-03-06
CVE-2023-0165 [MEDIUM] CWE-79 CVE-2023-0165: The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode
The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
nvd
CVE-2023-1155MEDIUMCVSS 5.4≤ 1.82023-03-02
CVE-2023-1155 [MEDIUM] CWE-79 CVE-2023-1155: The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_
The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web s
cvelistv5nvd
CVE-2021-24821MEDIUMCVSS 5.4fixed in 1.62022-03-07
CVE-2021-24821 [MEDIUM] CWE-79 CVE-2021-24821: The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to pe
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as well as the Text Preview field of a
nvd