Impact
The Cost Calculator Builder plugin exposes payment‑gateway secret keys (Stripe, Razorpay, PayPal) in the rendered page source for all versions up to 4.0.11 download a page containing a calculator and view the plaintext secret keys, thereby gaining full control over the merchant’s payment accounts. This is a classic information‑disclosure flaw (CWE‑200).
Affected Systems
The flaw affects the Stylemix Cost Calculator Builder WordPress plugin. All releases from the earliest version through 4.0.11 are impacted because the template body renders the gateway credentials. WordPress sites that have the plugin installed and the ‘use in all calculators’ option enabled for any payment gateway are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate baseline risk. The EPSS score is below 1 %, meaning attacks are currently considered unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been disclosed. Attackers only need to view the page source on any publicly reachable calculator page, with no authentication required.
OpenCVE Enrichment