Description
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
Published: 2026-10-04
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The Cost Calculator Builder plugin contains a flaw that allows sensitive information to be inserted into data that is sent from the website. An attacker who can trigger the plugin’s data transmission can obtain those embedded values, exposing confidential information by means of an information disclosure vulnerability classified as CWE-201.

Affected Systems

WordPress sites that have the StylemixThemes Cost Calculator Builder plugin installed in any version through 4.0.17 are affected. The plugin adds cost‑calculation functionality to a site and may store or forward user‑supplied cost data without adequately protecting it.

Risk and Exploitability

The CVSS score of 7.5 indicates a significant confidentiality impact. There is no EPSS score available and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the flaw can be exercised during normal plugin use or by accessing exposed plugin endpoints, allowing an attacker to retrieve sensitive data. With no documented exploit, patching remains the most reliable mitigation.

Generated by OpenCVE AI on October 4, 2026 at 13:51 UTC.

Remediation

Vendor Solution

Update the WordPress Cost Calculator Builder plugin to the latest available version (at least 4.0.18).


OpenCVE Recommended Actions

  • Update the WordPress Cost Calculator Builder plugin to version 4.0.18 or later as recommended by the vendor.
  • If a patch cannot be applied, uninstall or permanently disable the plugin to eliminate the risk.
  • Review the site’s data handling processes to ensure that no sensitive information is inadvertently transmitted or stored by WordPress or other plugins.

Generated by OpenCVE AI on October 4, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
Title WordPress Cost Calculator Builder plugin <= 4.0.17 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-04T09:08:23.508Z

Reserved: 2026-09-24T10:23:27.498Z

Link: CVE-2026-97307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T11:16:33.073

Modified: 2026-10-04T11:16:33.073

Link: CVE-2026-97307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T14:00:16Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data