plugin

Loan Comparison Vulnerabilities

6 known security issues reported for the Loan Comparison WordPress plugin. Most recent disclosed Dec 24, 2024.

3 medium

Running Loan Comparison on your site? Check whether your installed version is affected.

Scan your site free

Loan Comparison [loan-comparison] < 2.0.1

unknown

[en] The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...

Affected:
up to 2.0.1
Fixed in:
2.0.1
Disclosed:
Dec 24, 2024

CVE-2024-12814 on NVD →

Loan Comparison <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

CVSS:
6.4
Affected:
up to 2.0
Fixed in:
2.0.1
Disclosed:
Dec 23, 2024

CVE-2024-12814 on NVD →

Loan Comparison [loan-comparison] < 1.5.3

unknown

[en] The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Feb 21, 2023

CVE-2023-0366 on NVD →

Loan Comparison [loan-comparison] < 1.5.3

unknown

[en] The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Feb 21, 2023

CVE-2023-0442 on NVD →

Loan Comparison <= 1.5.2 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode

medium

The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes like 'amount', 'term', filters' in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary we...

CVSS:
6.4
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Jan 25, 2023

CVE-2023-0366 on NVD →

Loan Comparison <= 1.5.1 - Reflected Cross-Site Scripting

medium

The Loan Comparison plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a shortcode, in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 1.5.1
Fixed in:
1.5.3
Disclosed:
Jan 25, 2023

CVE-2023-0442 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database