Stored Cross-Site Scripting Vulnerability in Valuation Calculator Plugin for WordPress
CVE-2025-5753
6.4MEDIUM
What is CVE-2025-5753?
The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input validation and output escaping. This vulnerability affects all versions up to and including 1.3.2. Authenticated users with Contributor-level access or higher can exploit this weakness by injecting arbitrary web scripts through the ālinkā parameter. This malicious content executes whenever a user accesses an affected page, impacting the integrity and security of the site.
Affected Version(s)
Valuation Calculator * <= 1.3.2