Stored Cross-Site Scripting Vulnerability in WordPress Cost Calculator Builder Plugin
CVE-2024-4097

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 May 2024

Summary

The Cost Calculator Builder plugin for WordPress is exposed to a vulnerability that permits Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in its SVG upload functionality. This flaw affects all versions of the plugin up to and including 3.1.67. Unauthenticated attackers can exploit this vulnerability by injecting arbitrary web scripts into the plugin, which would execute whenever a user interacts with the compromised page. The risk of such an attack emphasizes the necessity for users to ensure their plugins are updated to protect against potential exploitation.

Affected Version(s)

Cost Calculator Builder * <= 3.1.67

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrea bocchetti
.