PT-2026-57407 · WordPress · Cost Calculator Builder

·

CVE-2026-10865

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cost Calculator Builder versions prior to 4.0.12
Description Sensitive information exposure occurs via the template body when the 'use in all calculators' option is enabled for one or more payment gateways in the global settings. Unauthenticated attackers can extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client secret from the page source of any page containing a calculator, potentially allowing full control of the merchant's payment gateway accounts.
Recommendations Update to version 4.0.12 or later. Disable the 'use in all calculators' option for payment gateways in the global settings as a temporary mitigation measure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10865

Affected Products

Cost Calculator Builder