CVE-2026-7753
Received Received - Intake

Unauthorized Data Export in Cost Calculator Builder WordPress Plugin

Vulnerability report for CVE-2026-7753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Wordfence

Description

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration β€” including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cost_calculator_builder cost_calculator_builder to 3.6.17 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Cost Calculator Builder plugin for WordPress has a vulnerability due to a missing capability check on the cost-calculator-custom-export-run AJAX action. This allows authenticated attackers with Subscriber-level access or higher to export sensitive data, including Stripe, PayPal, Razorpay, webhook, and reCAPTCHA secret keys.

Detection Guidance

Check WordPress sites running the Cost Calculator Builder plugin versions up to 3.6.17 for unauthorized export attempts. Review server logs for AJAX calls to cost-calculator-custom-export-run. Inspect user activity for Subscriber-level accounts accessing admin pages like /wp-admin/profile.php.

Impact Analysis

Attackers could gain access to sensitive payment and API keys, potentially leading to financial fraud, unauthorized transactions, or data breaches. If you use this plugin, attackers might steal credentials or manipulate calculator configurations.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to sensitive data. Exposure of payment keys or personal data may violate privacy regulations, resulting in legal penalties or reputational damage.

Mitigation Strategies

Update the Cost Calculator Builder plugin to the latest version. Remove Subscriber access if not required. Monitor for suspicious export activity. Rotate exposed API keys (Stripe, PayPal, Razorpay, webhook, reCAPTCHA) if the plugin was used.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart