CVE Explorer
CVE-2026-10865
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment gateway accounts. This exposure only occurs when the 'use in all calculators'
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Cost Calculator Builder","vendor":"stylemix","versions":[{"lessThanOrEqual":"4.0.11","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/problemTypes/0/descriptions/0
Source references
10 source assertions{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/functions.php#L748"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/8
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L28"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/7
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L281"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/5
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L61"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/6
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/includes/functions.php#L748"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/4
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L28"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/3
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L281"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L61"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/2
{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3578557%40cost-calculator-builder&new=3578557%40cost-calculator-builder"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/9
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/29de766d-5e7e-46b4-acac-feec5b33589e?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:195846ad02f824079014066c192679a0102efad03f38ccaeff5b9c574ec22dee · sha256:c395c81d2a05a679… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.