Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)
unknown
[en] The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2023
CVE-2023-0165 on NVD →
Cost Calculator <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions an...
- CVSS:
- 6.4
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 2, 2023
CVE-2023-1155 on NVD →
Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)
unknown
The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions an...
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 2, 2023
Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)
unknown
[en] The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissio...
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 2, 2023
CVE-2023-1155 on NVD →
Cost Calculator <= 1.8 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode
medium
The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nd_cost_calculator
shortcode in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with cont...
- CVSS:
- 6.4
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 13, 2023
CVE-2023-0165 on NVD →
Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)
unknown
Deactivate and delete. This plugin has been closed as of January 11, 2023 and is not available for download. This closure is temporary, pending a full review.
Marco Wotschka discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Cost Calculator Plugin. This could allow a malicious actor to i...
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2023
Cost Calculator [nd-projects] < 1.6 (closed)
unknown
[en] The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), a...
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Mar 7, 2022
CVE-2021-24821 on NVD →
Cost Calculator [nd-projects] < 1.8 (closed)
unknown
[en] The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Feb 28, 2022
CVE-2021-24820 on NVD →
Cost Calculator <= 1.8 - Authenticated Local File Inclusion
high
The Cost Calculator WordPress plugin through 1.7 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.8) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout
- CVSS:
- 7.5
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 1, 2022
CVE-2021-24820 on NVD →
Cost Calculator <= 1.5 - Contributor+ Stored Cross-Site Scripting
medium
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as wel...
- CVSS:
- 6.4
- Affected:
- up to 1.5
- Fixed in:
- 1.6
- Disclosed:
- Feb 1, 2022
CVE-2021-24821 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database