Impact
The Mortgage Calculator / Loan Calculator plugin for WordPress contains a stored XSS flaw in the 'mlcalc' shortcode. Unsanitized and unescaped shortcode attributes allow an attacker to embed arbitrary JavaScript that is saved and then executed whenever a page containing the shortcode is viewed. This could result in defacement, cookie theft, session hijacking or the delivery of additional malicious payloads. The vulnerability is classified as CWE‑79 and carries a moderate CVSS score of 6.4.
Affected Systems
WordPress installations using the Mortgage Calculator / Loan Calculator plugin with version 1.5.20 or earlier are affected. The flaw resides in the plugin’s core files (e.g., forms.inc.php and mlcalc.php) and applies to all users who can add or edit the shortcode on the site.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with at least contributor privileges who can create or revise page content that includes the mlcalc shortcode. Once injected, the stored script affects all users who view the compromised page, providing a persistent cross‑site scripting risk.
OpenCVE Enrichment
EUVD