Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Stored XSS.This issue affects Cost Calculator: from n/a through <= 7.4.
Published: 2025-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored XSS that occurs when the plugin fails to properly neutralize user input during page generation. Injected script is rendered on subsequent page loads when the affected data is displayed. This can cause arbitrary JavaScript to run in the browsers of any site visitor or administrator, enabling cookie theft, session hijacking, defacement, or further exploitation. The weakness matches CWE‑79, where input validation is insufficient.

Affected Systems

It affects the WordPress Cost Calculator plugin developed by QuanticaLabs, any installation running version 7.4 or earlier. Websites that have installed these plugin versions are vulnerable. The flaw impacts all users who view content that incorporates the stored data, which may include all logged‑in users or visitors, depending on site configuration.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity. An EPSS score below 1% implies a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Attackers would need to insert malicious content via the plugin’s storage interface; the necessity of admin access is inferred, not directly stated. Once stored, the malicious script is served to any user loading the affected page, making it potentially high impact to user browsers.

Generated by OpenCVE AI on May 1, 2026 at 06:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cost Calculator plugin to the latest release that addresses the XSS flaw.
  • If an update is unavailable, disable or remove the plugin from the site to eliminate the attack surface.
  • Review any data stored by the plugin, stripping script tags and escaping output to enforce proper input sanitization.

Generated by OpenCVE AI on May 1, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28554 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator allows Stored XSS. This issue affects Cost Calculator: from n/a through 7.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator allows Stored XSS. This issue affects Cost Calculator: from n/a through 7.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Stored XSS.This issue affects Cost Calculator: from n/a through <= 7.4.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator allows Stored XSS. This issue affects Cost Calculator: from n/a through 7.4.
Title WordPress Cost Calculator Plugin <= 7.4 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:29.774Z

Reserved: 2025-07-16T08:52:07.076Z

Link: CVE-2025-54046

cve-icon Vulnrichment

Updated: 2025-08-20T15:05:38.175Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:47.600

Modified: 2026-04-23T15:32:45.950

Link: CVE-2025-54046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:45:11Z

Weaknesses