Impact
The Cost Calculator Builder plugin contains a flaw that allows sensitive information to be inserted into data that is sent from the website. An attacker who can trigger the plugin’s data transmission can obtain those embedded values, exposing confidential information by means of an information disclosure vulnerability classified as CWE-201.
Affected Systems
WordPress sites that have the StylemixThemes Cost Calculator Builder plugin installed in any version through 4.0.17 are affected. The plugin adds cost‑calculation functionality to a site and may store or forward user‑supplied cost data without adequately protecting it.
Risk and Exploitability
The CVSS score of 7.5 indicates a significant confidentiality impact. There is no EPSS score available and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the flaw can be exercised during normal plugin use or by accessing exposed plugin endpoints, allowing an attacker to retrieve sensitive data. With no documented exploit, patching remains the most reliable mitigation.
OpenCVE Enrichment