Junglewise Threat Intelligence

CVE-2026-10865: StylemixThemes Cost Calculator Builder sensitive information exposure

CVE-2026-10865 · Severity: medium · CVSS 5.3 · Published 2026-07-11

Vendors: StylemixThemes.

Executive brief

The Cost Calculator Builder plugin for WordPress, which allows site owners to create price estimation forms, contains a security flaw that exposes sensitive payment credentials. An unauthenticated attacker can view the website's source code to find plaintext secret keys for Stripe, Razorpay, and PayPal. This could allow an attacker to gain unauthorized access to the merchant's payment gateway accounts and financial data.

Technical details

The Cost Calculator Builder plugin for WordPress is vulnerable to sensitive information exposure (CWE-200) in versions up to and including 4.0.11. The vulnerability exists within the frontend template rendering logic, which embeds plaintext Stripe secret keys, Razorpay secret keys, and PayPal client_secrets directly into the HTML page source. This occurs when the 'use in all calculators' option is enabled for payment gateways in the plugin's global settings. An unauthenticated remote attacker can exploit this by simply viewing the source code of any page where a calculator is published. This exposure grants the attacker the credentials necessary to interact with the merchant's payment provider APIs.

Affected products

  • StylemixThemes Cost Calculator Builder up to, and including, 4.0.11

Timeline

  • 2026-07-11: disclosed: Initial publication of the CVE record.
  • 2026-07-11: advisory

References

Related threats