Sceawere
Vulnerability Detail
CVE-2026-97307UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cost Calculator Builder Sensitive Data Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 4h ago
- Vendor
- StylemixThemes
- Product
- Cost Calculator Builder
- Attack Type
- Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-04T11:16:33.073Z",
"pubdate": "2026-10-04T11:16:33.073Z",
"executiveSummary": "The Cost Calculator Builder plugin for WordPress, developed by StylemixThemes, contains a vulnerability involving the insertion of sensitive information into sent data. This security flaw allows unauthorized entities to retrieve embedded sensitive information that should otherwise be protected.\nThis vulnerability is classified as an improper handling of sensitive information. The issue impacts Cost Calculator Builder versions ranging from n/a through 4.0.17.\nThe risk implication is significant as it potentially exposes configuration details, backend data, or user-defined sensitive information transmitted by the plugin during its normal operational lifecycle. An attacker with network access could exploit this flaw to harvest sensitive data without requiring administrative privileges, depending on how the plugin handles the request/response cycle.\nThe core of the issue lies in the insecure transmission or caching of data that contains sensitive components, which are subsequently reachable by unauthorized parties. Remediation requires an update to a version where this data handling has been secured.",
"technicalDetails": "The vulnerability is rooted in the insecure management of data streams within the Cost Calculator Builder plugin. Specifically, the application logic fails to properly sanitize or filter sensitive information before it is included in data packets sent to the client-side or stored in an accessible location. This constitutes an 'Insertion of Sensitive Information Into Sent Data' flaw, where the application inadvertently leaks internal data structures or sensitive configurations via its standard communication protocols.\nThe exploitation flow typically involves the intercepting of HTTP requests or responses generated by the plugin's frontend interface. Because the plugin includes sensitive data in these payloads—likely intended for internal processing—a malicious actor can examine the raw traffic to extract the exposed information. In some scenarios, if the data is reflected in publicly accessible API responses or serialized within the frontend client-side code, no specialized authentication or privilege level is required to retrieve the data.\nThe vulnerable component resides in the data preparation logic that constructs payloads for the Cost Calculator Builder features. Version 4.0.17 and all prior versions are affected by this design flaw. The root cause is the lack of a proper data classification and filtering mechanism within the plugin's output routines. By failing to strip sensitive attributes from the JSON payloads or client-bound objects, the plugin renders this information visible to anyone capable of inspecting the network traffic or the rendered page source.\nPost-exploitation, the impact is determined by the nature of the information exposed. If the leaked data includes database credentials, API keys, or personal user information, an attacker can leverage this to escalate their access, compromise the underlying database, or conduct further unauthorized operations on the WordPress environment. The technical exposure is global if the plugin is configured to render these calculators on public-facing pages, effectively removing the need for a targeted attack as the information is exposed as part of the page's standard resource delivery."
}