plugin

Nd Projects Vulnerabilities

10 known security issues reported for the Nd Projects WordPress plugin. Most recent disclosed Mar 6, 2023.

1 high 3 medium

Running Nd Projects on your site? Check whether your installed version is affected.

Scan your site free

Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)

unknown

[en] The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Mar 6, 2023

CVE-2023-0165 on NVD →

Cost Calculator <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions an...

CVSS:
6.4
Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Mar 2, 2023

CVE-2023-1155 on NVD →

Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)

unknown

The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions an...

Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Mar 2, 2023

Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)

unknown

[en] The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissio...

Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Mar 2, 2023

CVE-2023-1155 on NVD →

Cost Calculator <= 1.8 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

medium

The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nd_cost_calculator shortcode in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with cont...

CVSS:
6.4
Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Feb 13, 2023

CVE-2023-0165 on NVD →

Cost Calculator [nd-projects] <= 1.8 (unfixed + closed)

unknown

Deactivate and delete. This plugin has been closed as of January 11, 2023 and is not available for download. This closure is temporary, pending a full review. Marco Wotschka discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Cost Calculator Plugin. This could allow a malicious actor to i...

Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Feb 3, 2023

Cost Calculator [nd-projects] < 1.6 (closed)

unknown

[en] The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), a...

Affected:
up to 1.6
Fixed in:
1.6
Disclosed:
Mar 7, 2022

CVE-2021-24821 on NVD →

Cost Calculator [nd-projects] < 1.8 (closed)

unknown

[en] The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Feb 28, 2022

CVE-2021-24820 on NVD →

Cost Calculator <= 1.8 - Authenticated Local File Inclusion

high

The Cost Calculator WordPress plugin through 1.7 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.8) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout

CVSS:
7.5
Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Feb 1, 2022

CVE-2021-24820 on NVD →

Cost Calculator <= 1.5 - Contributor+ Stored Cross-Site Scripting

medium

The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as any page that embeds the calculator using the shortcode), as wel...

CVSS:
6.4
Affected:
up to 1.5
Fixed in:
1.6
Disclosed:
Feb 1, 2022

CVE-2021-24821 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database