{ "schema_version": "1.4.0", "id": "GHSA-7pg3-r4wv-7xmh", "modified": "2022-03-08T00:00:38Z", "published": "2022-03-01T00:00:32Z", "aliases": [ "CVE-2021-24820" ], "details": "The Cost Calculator WordPress plugin through 1.4 allows users with a role as low as Contributor to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24820" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/47652b24-a6f0-4bbc-834e-496b88523fe7" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/6dc5558f-d1f4-4ba3-b6f3-8c4e15d9738e" } ], "database_specific": { "cwe_ids": [ "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-02-28T09:15:00Z" } }