Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10865— Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys

Quick assessment

Affected
stylemix Cost Calculator Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

stylemixthemes cost calculator builder是stylemixthemes公司的一款成本估算与报价生成插件。 stylemixthemes cost calculator builder 4.0.11及之前版本存在信息泄露漏洞,该漏洞源于通过模板主体导致敏感信息暴露,可使未经身份验证的攻击者从包含计算器的页面源代码中提取明文Stripe secret key、Razorpay secret key和PayPal client_secret,从而完全控制商户的支付网关账户。

CVSS 5.3 · Medium EPSS 0.58% · P45

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
stylemix Cost Calculator Builder ≤ 4.0.11 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10865

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
Source: CVE Program / CVE List V5
Vulnerability Description
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment gateway accounts. This exposure only occurs when the 'use in all calculators' option is enabled for one or more payment gateways in the plugin's global settings.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
stylemixthemes cost calculator builder 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
stylemixthemes cost calculator builder是stylemixthemes公司的一款成本估算与报价生成插件。 stylemixthemes cost calculator builder 4.0.11及之前版本存在信息泄露漏洞,该漏洞源于通过模板主体导致敏感信息暴露,可使未经身份验证的攻击者从包含计算器的页面源代码中提取明文Stripe secret key、Razorpay secret key和PayPal client_secret,从而完全控制商户的支付网关账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
stylemix Cost Calculator Builder 0 ~ 4.0.11 -

II. Public POCs for CVE-2026-10865

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10865

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10865 (6)

Other References for CVE-2026-10865 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-10865

No comments yet


Leave a comment