EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_name'
mediumThe EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name' data and rendering it in the admin customer list without output escaping. This makes it possible for unauthenticated att...
- CVSS:
- 6.1
- Affected:
- up to 2.3.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 25, 2026