CVE-2026-97307: WordPress Cost Calculator Builder plugin <= 4.0.17 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/cost-calculator-builderto a version that resolves this vulnerability.Fixed in 4.0.18
Event History
Frequently Asked Questions
What level of access does an attacker need?
The vulnerability is remotely exploitable over the network and requires no prior privileges or user interaction. Exploitation is rated low complexity.
What is the likely security impact?
Successful exploitation can expose sensitive information. The provided scoring indicates high confidentiality impact, with no indicated integrity or availability impact.
How can I determine whether an installation is in scope?
Check whether StylemixThemes Cost Calculator Builder is installed and identify its version. The affected range is listed as through version 4.0.17.