Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a non...
- CVSS:
- 6.5
- Affected:
- up to 3.6.17
- Fixed in:
- 4.0.3
- Disclosed:
- Aug 4, 2026
CVE-2026-7753 on NVD →
Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded i...
- CVSS:
- 5.3
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.12
- Disclosed:
- Jul 10, 2026
CVE-2026-10865 on NVD →
Cost Calculator Builder <= 4.0.1 - Unauthenticated Price Manipulation and Insecure Direct Object Reference
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when used in combination with Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment AJAX action being regist...
- CVSS:
- 5.3
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- May 12, 2026
CVE-2025-14755 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.6.10
unknown
[en] The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessib...
- Affected:
- up to 3.6.10
- Fixed in:
- 3.6.10
- Disclosed:
- Jan 16, 2026
CVE-2025-14757 on NVD →
Cost Calculator Builder <= 3.6.9 - Missing Authorization to Unauthenticated Payment Status Bypass
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to...
- CVSS:
- 5.3
- Affected:
- up to 3.6.9
- Fixed in:
- 3.6.10
- Disclosed:
- Jan 15, 2026
CVE-2025-14757 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.6.4
unknown
[en] The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders tha...
- Affected:
- up to 3.6.4
- Fixed in:
- 3.6.4
- Disclosed:
- Dec 2, 2025
CVE-2025-12529 on NVD →
Cost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File Deletion
high
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject arbitrary file paths into the orders that are...
- CVSS:
- 8.8
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Dec 1, 2025
CVE-2025-12529 on NVD →
Cost Calculator Builder [cost-calculator-builder] <= 3.5.32 (unfixed)
unknown
[en] Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.
- Affected:
- up to 3.5.32
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-62049 on NVD →
Cost Calculator Builder <= 3.5.32 - Missing Authorization
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.5.32
- Fixed in:
- 3.5.33
- Disclosed:
- Oct 15, 2025
CVE-2025-62049 on NVD →
Cost Calculator Builder <= 3.5.32 - Authenticated (Subscriber+) Missing Authorization via get_cc_orders/update_order_status Functions
high
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_orders and update_order_status functions in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 8.1
- Affected:
- up to 3.5.32
- Fixed in:
- 3.5.33
- Disclosed:
- Oct 3, 2025
CVE-2025-9243 on NVD →
Cost Calculator Builder <= 3.2.74 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.74 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web script...
- CVSS:
- 4.4
- Affected:
- up to 3.2.74
- Fixed in:
- 3.5.0
- Disclosed:
- May 19, 2025
CVE-2025-48277 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.5.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder allows Stored XSS. This issue affects Cost Calculator Builder: from n/a through 3.2.74.
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- May 19, 2025
CVE-2025-48277 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.68
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder allows SQL Injection. This issue affects Cost Calculator Builder: from n/a through 3.2.65.
- Affected:
- up to 3.2.68
- Fixed in:
- 3.2.68
- Disclosed:
- Apr 17, 2025
CVE-2025-39587 on NVD →
Cost Calculator Builder <= 3.2.65 - Unauthenticated SQL Injection
high
The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.65 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...
- CVSS:
- 7.5
- Affected:
- up to 3.2.65
- Fixed in:
- 3.2.68
- Disclosed:
- Apr 16, 2025
CVE-2025-39587 on NVD →
Cost Calculator Builder <= 3.2.67 - Authenticated (Subscriber+) SQL Injection via order_ids Parameter
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter in all versions up to, and including, 3.2.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for auth...
- CVSS:
- 6.5
- Affected:
- up to 3.2.67
- Fixed in:
- 3.2.68
- Disclosed:
- Apr 10, 2025
CVE-2025-2128 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.66
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder allows Stored XSS. This issue affects Cost Calculator Builder: from n/a through 3.2.65.
- Affected:
- up to 3.2.66
- Fixed in:
- 3.2.66
- Disclosed:
- Mar 31, 2025
CVE-2025-31414 on NVD →
Cost Calculator Builder <= 3.2.65 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.65 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 3.2.65
- Fixed in:
- 3.2.66
- Disclosed:
- Mar 29, 2025
CVE-2025-31414 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.43
unknown
[en] The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
- Affected:
- up to 3.2.43
- Fixed in:
- 3.2.43
- Disclosed:
- Dec 18, 2024
CVE-2024-10892 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.1.43
unknown
[en] Missing Authorization vulnerability in StylemixThemes Cost Calculator Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost Calculator Builder: from n/a through 3.1.42.
- Affected:
- up to 3.1.43
- Fixed in:
- 3.1.43
- Disclosed:
- Dec 13, 2024
CVE-2023-40011 on NVD →
Cost Calculator Builder <= 3.2.42 - Cross-Site Request Forgery to Settings Update
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.42. This is due to missing or incorrect nonce validation on the save_settings() function. This makes it possible for unauthenticated attackers to update settings via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 3.2.42
- Fixed in:
- 3.2.43
- Disclosed:
- Nov 27, 2024
CVE-2024-10892 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.29
unknown
[en] The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
- Affected:
- up to 3.2.29
- Fixed in:
- 3.2.29
- Disclosed:
- Sep 30, 2024
CVE-2024-8379 on NVD →
Cost Calculator Builder <= 3.2.28 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection via the discount[direction] parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authent...
- CVSS:
- 4.9
- Affected:
- up to 3.2.28
- Fixed in:
- 3.2.29
- Disclosed:
- Sep 9, 2024
CVE-2024-8379 on NVD →
Cost Calculator Builder [cost-calculator-builder] <= 3.2.17 (unfixed)
unknown
[en] The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost Calculator Builder plugin. This mak...
- Affected:
- up to 3.2.17
- Fix:
- No patched version reported
- Disclosed:
- Sep 7, 2024
CVE-2024-6010 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.16
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.16
- Disclosed:
- Aug 29, 2024
CVE-2024-43144 on NVD →
Cost Calculator Builder <= 3.2.15 - Unauthenticated SQL Injection
critical
The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection via discount codes in versions up to, and including, 3.2.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...
- CVSS:
- 10
- Affected:
- up to 3.2.15
- Fixed in:
- 3.2.16
- Disclosed:
- Aug 7, 2024
CVE-2024-43144 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.13
unknown
[en] The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-leve...
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Jul 2, 2024
CVE-2024-6011 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.2.13
unknown
[en] The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level...
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Jul 2, 2024
CVE-2024-6012 on NVD →
Cost Calculator Builder <= 3.2.12 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level acc...
- CVSS:
- 4.4
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.13
- Disclosed:
- Jul 1, 2024
CVE-2024-6011 on NVD →
Cost Calculator Builder <= 3.2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level acce...
- CVSS:
- 4.3
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.13
- Disclosed:
- Jul 1, 2024
CVE-2024-6012 on NVD →
Cost Calculator Builder <= 3.1.42 - Improper Authorization
medium
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on multiple functions in versions up to, and including, 3.1.42. This makes it possible for authenticated attackers with Author permissions to manage the plugin's settings.
- CVSS:
- 5.4
- Affected:
- up to 3.1.43
- Fixed in:
- 3.1.43
- Disclosed:
- Aug 17, 2023
CVE-2023-40011 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.1.43
unknown
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on multiple functions in versions up to, and including, 3.1.42. This makes it possible for authenticated attackers with Author permissions to manage the plugin's settings.
- Affected:
- up to 3.1.43
- Fixed in:
- 3.1.43
- Disclosed:
- Aug 17, 2023
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 2.3.3
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Cost Calculator Builder plugin (versions < 2.3.3).
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Feb 28, 2022
Cost Calculator Builder [cost-calculator-builder] < 2.3.3
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Cost Calculator Builder plugin (versions < 2.3.3).
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Feb 28, 2022
Cost Calculator Builder [cost-calculator-builder] < 3.2.68
unknown
- Affected:
- up to 3.2.68
- Fixed in:
- 3.2.68
CVE-2025-2128 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 2.3.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
CVE-2023-33999 on NVD →
Cost Calculator Builder [cost-calculator-builder] < 3.5.33
unknown
- Affected:
- up to 3.5.33
- Fixed in:
- 3.5.33
CVE-2025-9243 on NVD →