PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14755 stylemix CVE debrief

The Cost Calculator Builder plugin for WordPress, when used with Cost Calculator Builder PRO, has an unauthenticated price manipulation vulnerability. This vulnerability allows attackers to add products to a cart with controlled prices due to insufficient authorization checks in the ccb_woocommerce_payment AJAX action. The action is registered via wp_ajax_nopriv, making it accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without proper authorization checks. Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks. This requires verifying  

Vendor
stylemix
Product
Cost Calculator Builder
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-09-30
Advisory published
2026-05-13
Advisory updated
2026-09-30

Who should care

Defenders responsible for WordPress installations using the Cost Calculator Builder plugin, especially those using the plugin in combination with Cost Calculator Builder PRO, should assess exposure and prioritize updates to mitigate potential price manipulation attacks.

Why it matters

The Cost Calculator Builder plugin for WordPress has an unauthenticated price manipulation vulnerability when used with Cost Calculator Builder PRO. Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks. The vulnerability allows attackers to add products to a cart with controlled prices due to insufficient authorization checks. This requires verification of plugin version and exposure, as well as prioritization of updates to mitigate the vulnerability.

  • Potential price manipulation by unauthenticated attackers.
  • Possible addition of products to cart with controlled prices.
  • Need for verification of plugin version and exposure.
  • Prioritization of updates to mitigate vulnerability.

Technical summary

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthenticated price manipulation and Insecure Direct Object Reference (IDOR) when used with Cost Calculator Builder PRO. The ccb_woocommerce_payment AJAX action is registered via wp_ajax_nopriv, making it accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without authorization checks.

Defensive priority

Defenders should prioritize verifying and updating the plugin to mitigate potential price manipulation attacks.

Recommended defensive actions

  • Verify and update the Cost Calculator Builder plugin to the latest version.
  • Restrict access to the ccb_woocommerce_payment AJAX action.
  • Monitor for suspicious activity related to price manipulation.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability exists in the ccb_woocommerce_payment AJAX action, which is accessible to unauthenticated users. The renderWooCommercePayment() function passes user-controlled data directly to CCBWooCheckout::init() without authorization checks.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14755 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14755

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14755 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14755

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBAjaxAction.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBOrderController.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.