Report
The Cost Calculator WordPress plugin through 1.7 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.8) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's Layout
Score:7.6
Severity:High
Version: 1.4
The plugin vendor has not patched this vulnerability at the moment.