PT-2024-37313 · WordPress · Cost Calculator Builder
Andrea Bocchetti
·
Published
2024-09-07
·
Updated
2024-10-23
·
CVE-2024-6010
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Cost Calculator Builder PRO plugin for WordPress versions up to, and including, 3.2.1
Description:
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation. This issue arises because the plugin allows the price field to be manipulated prior to processing via the
create cc order function, which is called from the Cost Calculator Builder plugin. This makes it possible for unauthenticated attackers to manipulate the price of orders submitted via the calculator.Recommendations:
For versions up to, and including, 3.2.1, update to version 3.2.17 or later to partially patch this vulnerability.
As a temporary workaround, consider restricting access to the
create cc order function until a more comprehensive patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cost Calculator Builder