CVE-2021-24904
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Date published : 2022-02-14
https://wpscan.com/vulnerability/7b80f89b-e724-41c5-aa03-21d1eef50f21
