Impact
The Estatik Mortgage Calculator plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation vulnerability that allows malicious input to be stored and later rendered as part of a page. When an attacker submits content that the plugin does not sanitize before storage, that content will be injected into the browser of any visitor to the affected page. The injected script can steal session cookies, exfiltrate data, or execute arbitrary browser‑side code, leading to data compromise or site defacement.
Affected Systems
All WordPress installations that use the Estatik Mortgage Calculator plugin, up to and including version 2.0.12, are impacted. No fixed release is currently documented in the information provided.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity risk, while the EPSS score of less than 1% suggests that exploitation is rare in the wild and the vulnerability is not listed in CISA’s KEV catalogue. Attackers must be able to submit the malicious content through an interface that the plugin accepts; the specific channel is not detailed, but it is likely a front‑end or administrative entry point. The title references a Local File Inclusion flaw, yet the description and CWE point exclusively to Stored XSS, so file disclosure does not appear to be a concern.
OpenCVE Enrichment
EUVD