Understanding the Cost Calculator Builder Payment Bypass Vulnerability
A significant security flaw has been found in the popular Cost Calculator Builder plugin for WordPress. This vulnerability, identified as an Unauthenticated Payment Status Bypass, affects websites using the plugin in conjunction with its PRO version. It essentially allows unauthorized individuals to mark an order’s payment as “completed” without actually making any payment. This could lead to financial losses for businesses relying on the plugin for their calculations and payment processing.
CVE Details
This vulnerability is officially identified as CVE-2025-14757.
- Product Name: Cost Calculator Builder plugin for WordPress (when used with Cost Calculator Builder PRO)
- Published Date: January 16, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts the Cost Calculator Builder plugin across all versions up to, and including, 3.6.9. It is critical to note that this specific bypass is exploitable only when the plugin is paired with the Cost Calculator Builder PRO add-on.
Current Status
As of its last modification date on January 23, 2026, the vulnerability has been thoroughly analyzed. This means security experts have investigated the issue and understand its mechanics, paving the way for effective solutions.
Severity Level
The vulnerability carries a Medium severity rating with a CVSS score of 5.3. A “Medium” severity indicates that while the vulnerability may not allow complete control over the affected system, it can still lead to significant negative impacts, such as financial fraud or disruption of services. In this case, the ability for unauthenticated users to bypass payment directly impacts the integrity of transactions.
Possible Solutions
The good news is that a fix for this vulnerability is available. To secure your WordPress website and prevent potential payment bypasses, it is crucial to update the Cost Calculator Builder plugin to version 3.6.10 or newer. This update addresses the underlying issue by implementing proper checks for user capabilities and order ownership, in addition to nonce verification. Regularly updating all your plugins, themes, and WordPress core is a fundamental security practice that helps protect your site from known vulnerabilities.
References
https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBAjaxAction.php#L98
https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes/CCBOrderController.php#L408
https://plugins.trac.wordpress.org/changeset/3437516/cost-calculator-builder/trunk/includes/classes/CCBOrderController.php?old=3426823&old_path=cost-calculator-builder%2Ftrunk%2Ftrunk%2Fincludes%2Fclasses%2FCCBOrderController.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/b8415e5f-17a4-425c-ac28-5dd886d1bcf1?source=cve


