CVE-2024-9354: Estatik Mortgage Calculator <= 2.0.11 - Reflected Cross-Site Scripting
The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' parameter in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9354?
CVE-2024-9354 has a medium severity rating due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-9354?
To fix CVE-2024-9354, update the Estatik Mortgage Calculator plugin to version 2.0.12 or later.
Who is affected by CVE-2024-9354?
All users running versions of the Estatik Mortgage Calculator plugin up to and including 2.0.11 are affected by CVE-2024-9354.
What is the attack vector for CVE-2024-9354?
The attack vector for CVE-2024-9354 is through the 'color' parameter, which lacks proper input sanitization and escaping.
Can CVE-2024-9354 be exploited by authenticated users?
CVE-2024-9354 can be exploited by unauthenticated attackers, making it a serious risk for all sites using the affected plugin.