CVE-2025-26907: WordPress Estatik Mortgage Calculator plugin <= 2.0.12 - Local File Inclusion vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage Calculator Estatik estatik-mortgage-calculator allows Stored XSS.This issue affects Mortgage Calculator Estatik: from n/a through <= 2.0.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26907?
CVE-2025-26907 has a moderate severity level due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-26907?
To fix CVE-2025-26907, update the Estatik Mortgage Calculator plugin to version 2.0.13 or later.
What versions are affected by CVE-2025-26907?
CVE-2025-26907 affects Estatik Mortgage Calculator versions from n/a up to 2.0.12.
Is my website at risk if I use an affected version for CVE-2025-26907?
Yes, if your website uses Estatik Mortgage Calculator version 2.0.12 or earlier, it is vulnerable to stored XSS attacks.
What should I do if my site has been exploited due to CVE-2025-26907?
If your site has been exploited, it's crucial to remove the malicious code, patch the vulnerability, and review your current security practices.