---
id: CVE-2026-10865
title: >-
  The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive
  Information Exposure in all versions up to, and including, 4.0.11 via the
  (template body)
summary: >-
  The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive
  Information Exposure in all versions up to, and including, 4.0.11 via the
  (template body). This makes it possible for unauthenticated attackers to
  extract the pl…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10865'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/functions.php#L748
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L28
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L281
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/templates/frontend/render.php#L61
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/includes/functions.php#L748
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L28
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L281
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/4.0.5/templates/frontend/render.php#L61
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3578557%40cost-calculator-builder&new=3578557%40cost-calculator-builder
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/29de766d-5e7e-46b4-acac-feec5b33589e?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00576
epssPercentile: 0.45086
ingestedAt: '2026-07-11T23:16:20.678Z'
---

## Overview

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment gateway accounts. This exposure only occurs when the 'use in all calculators' option is enabled for one or more payment gateways in the plugin's global settings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
