PT-2026-40557 · Stylemix · Cost Calculator Builder

Andrea Bocchetti

·

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2025-14755

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when used in combination with Cost Calculator Builder PRO. This is due to the ccb woocommerce payment AJAX action being registered via wp ajax nopriv, making it accessible to unauthenticated users, and the renderWooCommercePayment() function passing user-controlled data directly to CCBWooCheckout::init() without authorization checks. This makes it possible for unauthenticated attackers to add WooCommerce products to their cart with attacker-controlled prices.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14755

Affected Products

Cost Calculator Builder