The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.1.96. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost Calculator Builder plugin. This makes it possible for unauthenticated attackers to manipulate the price of orders submitted via the calculator. Note: this vulnerability was partially patched with the release of Cost Calculator Builder version 3.2.17.
History

Mon, 09 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes cost Calculator Builder Pro
CPEs cpe:2.3:a:stylemixthemes:cost_calculator_builder_pro:*:*:*:*:*:*:*:*
Vendors & Products Stylemixthemes
Stylemixthemes cost Calculator Builder Pro
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 07 Sep 2024 11:30:00 +0000

Type Values Removed Values Added
Description The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.1.96. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost Calculator Builder plugin. This makes it possible for unauthenticated attackers to manipulate the price of orders submitted via the calculator. Note: this vulnerability was partially patched with the release of Cost Calculator Builder version 3.2.17.
Title Cost Calculator Builder PRO <= 3.1.96 - Unauthenticated Price Manipulation
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-07T11:17:06.172Z

Updated: 2024-09-09T13:52:45.273Z

Reserved: 2024-06-14T16:33:02.308Z

Link: CVE-2024-6010

cve-icon Vulnrichment

Updated: 2024-09-09T13:52:38.062Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-07T12:15:12.067

Modified: 2024-09-09T13:03:38.303

Link: CVE-2024-6010

cve-icon Redhat

No data.