PT-2026-57407 · WordPress · Cost Calculator Builder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cost Calculator Builder versions prior to 4.0.12
Description
Sensitive information exposure occurs via the template body when the 'use in all calculators' option is enabled for one or more payment gateways in the global settings. Unauthenticated attackers can extract the plaintext Stripe secret key, Razorpay secret key, and PayPal
client secret from the page source of any page containing a calculator, potentially allowing full control of the merchant's payment gateway accounts.Recommendations
Update to version 4.0.12 or later.
Disable the 'use in all calculators' option for payment gateways in the global settings as a temporary mitigation measure.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cost Calculator Builder