Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the cost-calculator-custom-export-run AJAX action (handler CCBExportImport::export_calculators()) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding ccb_export_nonce is broadcast on every wp-admin page (including pages reachable to Subscribers, such as /wp-admin/profile.php) by the ccb_add_admin_nonces callback hooked to admin_head. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.
Affected products
1- Range: <=3.6.17
Patches
Vulnerability mechanics
References
7- plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/classes/CCBExportImport.phpmitre
- plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.phpmitre
- plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.phpmitre
- plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.phpmitre
- plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/includes/classes/CCBExportImport.phpmitre
- plugins.trac.wordpress.org/changesetmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/89de168e-1bce-4e11-a765-afc1d7dce8femitre
News mentions
0No linked articles in our index yet.