CVE detail
CVE-2021-24904 — CVE-2021-24904
Published 2022-02-14 · Modified 2026-06-17 · Vendor lenderd · Product mortgage_calculators_wp · Source nvd
MEDIUM
severity
CVSS-derived band
0.0506
EPSS probability
exploitation probability, 30d
92.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References