Description
Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.
Published: 2025-11-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Stylemix Cost Calculator Builder plugin for WordPress. Because the plugin does not enforce proper access control, users who are not privileged can perform privileged actions—such as viewing, editing, or deleting calculators—by simply accessing the plugin’s endpoints. This flaw is classified as CWE‑862, indicating an insufficient authentication or authorization mechanism. The outcome is that an attacker could gain unauthorized access to configuration data or alter calculator settings, potentially compromising the integrity of the site’s financial calculations.

Affected Systems

Affected software is the Stylemix Cost Calculator Builder plugin for WordPress. All releases from the origination point up to and including version 3.5.32 are impacted; earlier unspecified versions are also included in the “through <= 3.5.32” statement. The vendor is Stylemix. No specific sub‑components or versions within the plugin are singled out beyond the overall version range.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the medium severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog, suggesting no widespread or actively leveraged exploits. The attack vector is likely remote, via HTTP requests to the plugin’s administrative endpoints, and an attacker would need to be able to target a WordPress site running a vulnerable version of the plugin. No evidence of a publicly available exploit is provided, so the practical risk depends on the attacker’s ability to reach the vulnerable site.

Generated by OpenCVE AI on April 29, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Cost Calculator Builder plugin to version 3.5.33 or later.
  • If an immediate update is not possible, restrict access to the plugin’s administrative REST API endpoints so that only users with appropriate administrator roles can invoke them.
  • Review and harden WordPress role permissions to ensure that only authorized users can create, edit, or delete calculators.

Generated by OpenCVE AI on April 29, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes cost Calculator Builder
Wordpress
Wordpress wordpress
Vendors & Products Stylemixthemes
Stylemixthemes cost Calculator Builder
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.
Title WordPress Cost Calculator Builder plugin <= 3.5.32 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Stylemixthemes Cost Calculator Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:00.166Z

Reserved: 2025-10-07T15:34:31.733Z

Link: CVE-2025-62049

cve-icon Vulnrichment

Updated: 2025-11-06T21:11:55.063Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:11.440

Modified: 2026-04-27T17:16:31.013

Link: CVE-2025-62049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:15:23Z

Weaknesses