---
id: CVE-2025-14755
title: >-
  The Cost Calculator Builder plugin for WordPress is vulnerable to
  Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR)
  in all versions up to, and including, 4.0.1 only when used in combination with
  Cost Calculat…
summary: >-
  The Cost Calculator Builder plugin for WordPress is vulnerable to
  Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR)
  in all versions up to, and including, 4.0.1 only when used in combination with
  Cost Calculat…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-05-13'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14755'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBAjaxAction.php#L99
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBOrderController.php#L484
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/fe684f43-8442-4b29-84a8-da8c6863e62b?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00227
epssPercentile: 0.12177
ingestedAt: '2026-09-30T22:27:27.789Z'
---

## Overview

The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when used in combination with Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the renderWooCommercePayment() function passing user-controlled data directly to CCBWooCheckout::init() without authorization checks. This makes it possible for unauthenticated attackers to add WooCommerce products to their cart with attacker-controlled prices.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
