← WordPress Vulnerabilities
WordPress security by component

Mortgage Calculator Estatik

Mortgage Calculator Estatik is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Feb 25, 2025; the highest CVE/CNA score is 7.5.

Plugin slug: estatik-mortgage-calculator

CVE-2025-26907: Mortgage Calculator Estatik: Cross-site scripting

Mortgage Calculator Estatik is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 25, 2025
Safe version guidanceSee mitigation notes
Safe version
Feb 25, 2025 CVE-2025-26907
Mortgage Calculator Estatik: Cross-site scripting
Mortgage Calculator Estatik is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.5
NVDPending
Jan 07, 2025 CVE-2024-9354
Estatik Mortgage Calculator: Cross-site scripting
Estatik Mortgage Calculator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 27, 2023 CVE-2023-28490
Estatik Mortgage Calculator: Cross-site scripting
Estatik Mortgage Calculator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 06, 2023 CVE-2023-40601
Estatik Mortgage Calculator: Cross-site scripting
Estatik Mortgage Calculator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1