Impact
The Loan Calculator plugin contains a flaw that allows a malicious actor to send a forged request from a victim’s browser, resulting in the plugin storing attacker-supplied JavaScript. When a user later views the stored data, the script executes in the victim’s browser, potentially compromising account data or enabling further attacks. The weakness is a CSRF‑to‑Stored XSS issue, listed as CWE‑352.
Affected Systems
The flaw affects the Casey Johnson Loan Calculator plugin for WordPress versions up to and including 1.3. All sites running the plugin in this version range are vulnerable; no specific WordPress core versions are mentioned.
Risk and Exploitability
The CVSS base score of 7.1 indicates moderate‑to‑high severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation at this time. The vulnerability is not currently featured in the CISA KEV catalog. Attackers would need to entice a logged‑in user to visit a crafted link or otherwise send the forged request, after which the produced stored script would affect all users viewing the affected content.
OpenCVE Enrichment
EUVD