First published: Thu Apr 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator allows Stored XSS. This issue affects Loan Calculator: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Casey Johnson Loan Calculator | <=1.3 | |
WordPress Loan Calculator plugin | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46442 is a critical vulnerability that allows Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS).
To fix CVE-2025-46442, update the Loan Calculator to the latest version above 1.3 or apply appropriate security patches recommended by the vendor.
CVE-2025-46442 affects versions of the Loan Calculator from n/a up to and including version 1.3.
CVE-2025-46442 is associated with Cross-Site Request Forgery (CSRF) which can lead to Stored XSS attacks.
Users and websites utilizing the Casey Johnson Loan Calculator and WordPress Loan Calculator plugin versions up to 1.3 are affected by CVE-2025-46442.