peter bassill · operator
$ cve CVE-2021-24272 JSON

CVE-2021-24272 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS1.82% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2021-05-05
Last modified2026-06-17

Affected (1)

VendorProduct
codeinitiatorfitness calculators

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD