Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stylemixthemes
Stylemixthemes cost Calculator Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Stylemixthemes
Stylemixthemes cost Calculator Builder Wordpress Wordpress wordpress |
Fri, 16 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the complete() function only verifying a nonce without checking user capabilities or order ownership. Since nonces are exposed to all visitors via window.ccb_nonces in the page source, any unauthenticated attacker can mark any order's payment status as "completed" without actual payment. | |
| Title | Cost Calculator Builder <= 3.6.9 - Missing Authorization to Unauthenticated Payment Status Bypass | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-16T13:04:53.115Z
Reserved: 2025-12-15T22:56:12.691Z
Link: CVE-2025-14757
Updated: 2026-01-16T13:04:48.808Z
Status : Received
Published: 2026-01-16T09:15:59.663
Modified: 2026-01-16T09:15:59.663
Link: CVE-2025-14757
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:41:36Z