WordPress · Cost Calculator Builder · CVE-2026-10865
**Name of the Vulnerable Software and Affected Versions**
Cost Calculator Builder versions prior to 4.0.12
**Description**
Sensitive information exposure occurs via the template body when the 'use in all calculators' option is enabled for one or more payment gateways in the global settings. Unauthenticated attackers can extract the plaintext Stripe secret key, Razorpay secret key, and PayPal `client secret` from the page source of any page containing a calculator, potentially allowing full control of the merchant's payment gateway accounts.
**Recommendations**
Update to version 4.0.12 or later.
Disable the 'use in all calculators' option for payment gateways in the global settings as a temporary mitigation measure.