PatchSiren cyber security CVE debrief
CVE-2025-14755 stylemix CVE debrief
The Cost Calculator Builder plugin for WordPress, when used with Cost Calculator Builder PRO, has an unauthenticated price manipulation vulnerability. This vulnerability allows attackers to add products to a cart with controlled prices due to insufficient authorization checks in the ccb_woocommerce_payment AJAX action. The action is registered via wp_ajax_nopriv, making it accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without proper authorization checks. Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks. This requires verifying
- Vendor
- stylemix
- Product
- Cost Calculator Builder
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for WordPress installations using the Cost Calculator Builder plugin, especially those using the plugin in combination with Cost Calculator Builder PRO, should assess exposure and prioritize updates to mitigate potential price manipulation attacks.
Why it matters
The Cost Calculator Builder plugin for WordPress has an unauthenticated price manipulation vulnerability when used with Cost Calculator Builder PRO. Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks. The vulnerability allows attackers to add products to a cart with controlled prices due to insufficient authorization checks. This requires verification of plugin version and exposure, as well as prioritization of updates to mitigate the vulnerability.
- Potential price manipulation by unauthenticated attackers.
- Possible addition of products to cart with controlled prices.
- Need for verification of plugin version and exposure.
- Prioritization of updates to mitigate vulnerability.
Technical summary
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthenticated price manipulation and Insecure Direct Object Reference (IDOR) when used with Cost Calculator Builder PRO. The ccb_woocommerce_payment AJAX action is registered via wp_ajax_nopriv, making it accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without authorization checks.
Defensive priority
Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks.
Recommended defensive actions
- Verify and update the Cost Calculator Builder plugin to the latest version.
- Restrict access to the ccb_woocommerce_payment AJAX action.
- Monitor for suspicious activity related to price manipulation.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability exists in the ccb_woocommerce_payment AJAX action, which is accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without authorization checks.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14755 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14755
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14755 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14755
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBAjaxAction.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBOrderController.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.