PT-2026-3234 · WordPress · Cost Calculator Builder

Andrea Bocchetti

·

Published

2026-01-16

·

Updated

2026-01-23

·

CVE-2025-14757

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cost Calculator Builder plugin for WordPress versions prior to 3.7.0
Description The Cost Calculator Builder plugin for WordPress is susceptible to an unauthenticated payment status bypass. This occurs because the complete payment AJAX action is registered via wp ajax nopriv, allowing access to unauthenticated users. The complete() function only verifies a nonce, without checking user capabilities or order ownership. Nonces are exposed to all visitors via window.ccb nonces in the page source, enabling an attacker to mark any order's payment status as "completed" without actual payment. The issue requires the use of both Cost Calculator Builder and Cost Calculator Builder PRO.
Recommendations Update the Cost Calculator Builder plugin to version 3.7.0 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14757

Affected Products

Cost Calculator Builder