CVE-2026-97307: Cost Calculator Builder Risk
TL;DR - CVE-2026-97307 is a CVSS 7.5 sensitive-data exposure vulnerability in StylemixThemes Cost Calculator Builder through version 4.0.17. - The vulnerable endpoint, authentication requirement, exposed fields, and fixed version are not confirmed. - No verified public PoC or active exploitation is known; inventory and disable affected deployments if practical.
Summary
CVE-2026-97307 affects StylemixThemes Cost Calculator Builder, a WordPress plugin used to build interactive pricing and calculation forms. The NVD classifies the issue as “Insertion of Sensitive Information Into Sent Data,” while Patchstack describes it as sensitive data exposure. Available records state that affected versions extend through 4.0.17, but they do not provide a lower version bound.
| Field | Assessment |
|---|---|
| CVE | CVE-2026-97307 |
| Severity | High |
| CVSS v3 base score | 7.5 |
| CVSS vector | Not provided in the retrieved NVD record |
| Attack vector | Unknown from available records |
| Authentication required | Unknown from available records |
| Affected product | StylemixThemes Cost Calculator Builder |
| Affected versions | Through 4.0.17, including <= 4.0.17 according to Patchstack |
| Patch available | No fixed version identified |
| CISA KEV status | Not listed |
The operational risk is potential disclosure of information embedded in data sent by the plugin. Available research does not establish whether exploitation requires a logged-in WordPress account, a particular form configuration, access to a public calculator, or another prerequisite. Treat internet-facing installations as potentially exposed until the vulnerable behavior and remediation status are clarified.
Analyst’s Take: The first priority is exposure reduction, not exploit-path speculation. Inventory sites running the plugin, identify public calculators and sensitive workflows, and disable or remove the plugin where practical while monitoring for a validated fix.
Root Cause
The confirmed weakness category is CWE-style insertion of sensitive information into sent data. In practical terms, the plugin may include sensitive values in an HTTP request, response, generated calculation payload, or another data exchange where those values should not be present. The CVE description uses the phrase “Retrieve Embedded Sensitive Data,” but does not identify the affected function, endpoint, parameter, database record, or serialization format.
The precise root-cause code path remains unverified. Available source material does not establish whether the issue involves excessive data returned by an AJAX action, an unauthenticated REST endpoint, client-side configuration exposure, stored calculator data, or another mechanism. Defenders should not assume a specific exploit path or authentication bypass based solely on the CVE description.
The exposed data type is also unknown, so impact assessment should include both calculator submissions and plugin configuration. Review whether forms collect names, email addresses, phone numbers, business information, pricing details, internal identifiers, or other customer-provided data. If the plugin supports regulated or confidential workflows, involve privacy and compliance owners in the assessment.
Who’s Exposed
The affected product is StylemixThemes Cost Calculator Builder for WordPress. NVD reports the affected range as “from n/a through 4.0.17,” meaning that no lower bound was supplied in the retrieved record. Patchstack identifies the affected condition as Cost Calculator Builder <= 4.0.17. Interpret this as all versions up to and including 4.0.17 unless the vendor provides a narrower range.
Sites are exposed when the vulnerable plugin is installed and active, particularly where calculators are publicly reachable or process sensitive submissions. Available records do not confirm whether inactive installations remain exploitable, but inactive copies can still create maintenance and supply-chain risk. Remove unused copies rather than relying only on deactivation.
Organizations managing multiple WordPress sites should document ownership, exposure, data sensitivity, and remediation status as part of their third-party risk management process. The following inventory checks can identify installed versions across common WordPress environments:
wp plugin get cost-calculator-builder --field=version
wp plugin status cost-calculator-builder
wp plugin path cost-calculator-builder
For a fleet, collect the result from each WordPress site and flag versions at or below 4.0.17. Do not treat a version above 4.0.17 as definitively safe until a vendor or advisory source identifies a fixed release, because the available research does not name one.
Severity Breakdown
The assigned CVSS v3 base score is 7.5, which is generally considered High. The retrieved NVD response did not include the CVSS vector string. As a result, the individual metric values, including attack vector, attack complexity, privileges required, user interaction, scope, confidentiality, integrity, and availability, cannot be reliably reconstructed.
The quick-reference fields therefore remain explicitly unknown rather than inferred. In particular, a 7.5 score does not by itself prove that the issue is remotely exploitable without authentication. Avoid converting the numeric score into an assumed firewall or access-control rule.
The known classification points primarily to confidentiality impact. No available source confirms integrity or availability impact, and no source identifies the exact information exposed. Risk prioritization should combine the score with deployment context: public calculators, sensitive submission workflows, high-value WordPress sites, and sites lacking compensating controls deserve faster review.
Exploitation Status
CVE-2026-97307 is not listed in the CISA Known Exploited Vulnerabilities catalog based on the lookup performed for this assessment. There is no CISA date added, due date, required action, or ransomware-campaign designation for this CVE. This means CISA has not provided KEV confirmation, not that exploitation is impossible or definitively absent.
No verified public proof-of-concept repository or exploit was identified in the reviewed sources. No confirmed evidence of in-the-wild exploitation was identified either. Search results concerning unrelated vulnerabilities, including Citrix NetScaler issues, must not be treated as evidence for this CVE.
The social and EPSS metadata on this page should not be read as independent threat intelligence. The available research did not provide a validated EPSS result or mention count. Continue monitoring vendor advisories, Patchstack, NVD updates, threat-intelligence feeds, and internal WordPress telemetry. For comparison with other tracked vulnerabilities, review our coverage of CVE-2026-57989, while keeping each issue’s affected product and evidence separate.
Sources
The NVD record identifies CVE-2026-97307, assigns a CVSS v3 base score of 7.5, classifies the weakness as insertion of sensitive information into sent data, and reports affected Cost Calculator Builder versions through 4.0.17. The retrieved NVD response did not include a CVSS vector, vulnerable endpoint, authentication requirement, or fixed version.
Patchstack identifies the issue as sensitive data exposure in the WordPress Cost Calculator Builder plugin and lists the affected condition as <= 4.0.17. Its available metadata states that mitigation is not available. In the reviewed material, it does not provide enough technical detail to confirm the exact exploit path or a fixed release.
- NVD: CVE-2026-97307
- Patchstack: Cost Calculator Builder advisory
- CISA Known Exploited Vulnerabilities Catalog
The CVE is not currently listed in CISA KEV, and no verified public PoC or confirmed in-the-wild exploitation was identified in the reviewed sources. Revisit these findings as the advisory, vendor release information, and threat intelligence are updated.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.
Detection Guidance
Start by identifying WordPress sites with Cost Calculator Builder installed, including staging, backup, and tenant environments. Record the installed version, whether the plugin is active, which calculators are public, and whether forms process personal, financial, commercial, or operationally sensitive data.
The vulnerable endpoint and request format are not published in the available material, so there is no CVE-specific network signature that can be responsibly supplied. Review web-server, WAF, reverse-proxy, and WordPress logs for requests to plugin-related paths and AJAX activity. A useful first-pass query for normalized access logs is:
grep -Ei \
'cost-calculator-builder|admin-ajax\.php|wp-json|calculator' \
/var/log/nginx/access.log /var/log/apache2/access.log 2>/dev/null
This is a hunting filter, not a confirmed exploit signature. It will produce legitimate traffic and cannot distinguish exploitation without the affected action or parameter. Preserve matching requests and responses where permitted. Look for unusual access patterns such as repeated requests from one source, high-volume requests to public calculators, unexpected response sizes, sensitive values in response bodies, or access from clients that normally do not submit forms.
A SIEM query can help establish a baseline:
http.request.uri.path contains "admin-ajax.php"
OR http.request.uri.path contains "wp-json"
OR url.original contains "cost-calculator-builder"
| stats count(), sum(http.response.body.bytes) by source.ip, host.name, http.request.method
| sort - sum(http.response.body.bytes) desc
Field names vary by SIEM, and this query is intentionally generic because the exact vulnerable route is unknown. Investigate any evidence that plugin responses contain data belonging to another user or site visitor. If disclosure is suspected, rotate exposed credentials, tokens, or secrets and follow applicable breach-notification procedures.
Remediation Steps
No fixed version was identified in the retrieved NVD or Patchstack material. Patchstack metadata states Mitigation available: false, and the reviewed records do not establish a release newer than 4.0.17 that resolves the issue. Do not claim that upgrading to an unspecified version fixes CVE-2026-97307. Verify the vendor’s current changelog and security advisory before deploying an update.
Inventory affected sites and, where the plugin is not required, deactivate and remove it:
wp plugin deactivate cost-calculator-builder
wp plugin delete cost-calculator-builder
Use removal only after confirming that the site does not depend on the plugin and that configuration or calculator data has been exported according to business requirements. If the plugin must remain installed temporarily, limit public access to affected calculator pages, place the site behind an authenticated reverse proxy where feasible, restrict administrative access, and apply WAF rules based on observed application behavior. These are compensating controls, not a confirmed fix.
Review and protect data generated by the plugin. Disable unnecessary calculators and integrations, reduce retention of submitted information, restrict access to WordPress exports and backups, and inspect cached pages or proxy logs for sensitive values. If the plugin handled credentials, API keys, or session-like tokens, rotate them after investigating exposure. A password manager such as Try 1Password → can help teams generate and store replacement credentials securely, but it does not replace investigation or credential rotation.
For broader visibility across administrator workstations and servers, organizations may also consider endpoint security and monitoring tools such as Get Bitdefender →. These tools are supplemental and do not remediate the vulnerable WordPress plugin itself.
Continue checking the plugin’s official update channel and Patchstack advisory for a validated fixed version. Once a fix is published, test it in staging, confirm the installed version, and deploy through the organization’s normal change process:
wp plugin update cost-calculator-builder
wp plugin get cost-calculator-builder --field=version
Run the update command only after confirming that the available release is explicitly documented as addressing this vulnerability. After updating, review logs and application behavior for continued disclosure, and remove temporary access restrictions only after validation.