CVE-2026-7753 PUBLISHED

Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure

Assigner: Wordfence
Reserved: 03.05.2026 Published: 05.08.2026 Updated: 05.08.2026

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the cost-calculator-custom-export-run AJAX action (handler CCBExportImport::export_calculators()) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding ccb_export_nonce is broadcast on every wp-admin page (including pages reachable to Subscribers, such as /wp-admin/profile.php) by the ccb_add_admin_nonces callback hooked to admin_head. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor stylemix
Product Cost Calculator Builder
Versions Default: unaffected
  • affected from 0 to 3.6.17 (incl.)

Credits

  • momopon1415 finder

References

Problem Types

  • CWE-862 Missing Authorization CWE