Impact
An attacker can inject malicious script into the output of the Simple Finance Calculator plugin because user input is not properly neutralized during page generation. This reflected XSS flaw allows the attacker to execute arbitrary code in the browsers of site visitors, potentially stealing session cookies, defacing the site, or facilitating further attacks such as credential phishing or drive‑by downloads.
Affected Systems
All installations of the WordPress "Simple Finance Calculator" plugin by weissmike that use version 1.0 or earlier are affected. The plugin’s documentation lists the vulnerability as present from the initial release up to and including 1.0.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, yet the EPSS score is below 1 %, suggesting that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a crafted URL or form input on any page that displays the calculator, allowing the attacker to embed script tags that are reflected back and executed in the victim’s browser.
OpenCVE Enrichment