Sploitus

CVE-2021-24822

1 known exploit for CVE-2021-24822

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parameters

Affected products
Stylish Cost Calculator
Stylishcostcalculator Stylish Cost Calculator
< 7.0.4
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.3% (23th percentile)
Weakness
CWE-352, CWE-79
NVD status
Modified
Published
2021-11-29
CVE-2021-24822 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24822

Proof-of-concept code and exploit modules indexed by Sploitus