PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97307 StylemixThemes CVE debrief

A vulnerability in the Cost Calculator Builder plugin allows sensitive data exposure. This issue affects Cost Calculator Builder from n/a through 4.0.17. The plugin's vulnerability could lead to potential data exposure in installations. Defenders should assess their environments for potential exposure and prioritize remediation efforts based on the plugin's version and usage within their systems. The vulnerability's impact may vary depending on the specific configurations and data handled by the plugin.

Vendor
StylemixThemes
Product
Cost Calculator Builder
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for WordPress installations with the Cost Calculator Builder plugin should assess potential exposure and prioritize remediation. This includes reviewing the plugin's version, assessing the potential impact on affected systems, and planning for vendor-supported updates or mitigations. Security teams and vulnerability management teams should also be aware of the potential risks associated with the

Why it matters

Defenders should prioritize verifying exposure and assessing potential data exposure in their environments due to the sensitive data exposure vulnerability in Cost Calculator Builder.

  • Potential sensitive data exposure in Cost Calculator Builder installations
  • Need to verify exposure and assess potential impact on affected systems

Technical summary

The Cost Calculator Builder plugin has a vulnerability that allows sensitive data exposure. This issue affects Cost Calculator Builder from n/a through 4.0.17. The vulnerability could allow attackers to retrieve embedded sensitive data. Defenders should focus on verifying exposure and assessing potential data exposure in their environments. The plugin's vulnerability is related to its handling of sensitive information, which could be exploited to gain unauthorized access to sensitive data.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential data exposure in their environments.

Recommended defensive actions

  • Verify exposure of Cost Calculator Builder installations in your environment
  • Assess potential data exposure and prioritize remediation
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the scope of affected systems and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97307 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97307

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97307 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97307

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.