Stored Cross-Site Scripting Vulnerability in Reactive Mortgage Calculator Plugin by Afzal_Du
CVE-2025-27341

6.5MEDIUM

Key Information:

Vendor
Afzal Du
Status
Reactive Mortgage Calculator
Vendor
CVE Published:
24 February 2025

Summary

The Reactive Mortgage Calculator plugin by Afzal_Du is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user inputs during web page generation. This vulnerability allows an attacker to inject malicious scripts that can be stored and executed in the context of users accessing the affected version of the plugin, potentially compromising the integrity and security of user data.

Affected Version(s)

Reactive Mortgage Calculator <= 1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.