Stored Cross-Site Scripting Vulnerability in WordPress Cost Calculator Builder Plugin
CVE-2024-4097
7.2HIGH
Summary
The Cost Calculator Builder plugin for WordPress is exposed to a vulnerability that permits Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in its SVG upload functionality. This flaw affects all versions of the plugin up to and including 3.1.67. Unauthenticated attackers can exploit this vulnerability by injecting arbitrary web scripts into the plugin, which would execute whenever a user interacts with the compromised page. The risk of such an attack emphasizes the necessity for users to ensure their plugins are updated to protect against potential exploitation.
Affected Version(s)
Cost Calculator Builder * <= 3.1.67
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
andrea bocchetti