Junglewise Threat Intelligence

CVE-2026-14900: StylemixThemes Cost Calculator Builder PRO remote code execution in js_to_php

CVE-2026-14900 · Severity: critical · CVSS 9.8 · Published 2026-07-29

Vendors: StylemixThemes.

Executive brief

The Cost Calculator Builder PRO plugin for WordPress, which allows businesses to create interactive price estimation forms, contains a critical security flaw. An attacker can exploit this vulnerability to remotely execute malicious code on the website's server without needing to log in. This could lead to a complete takeover of the website, theft of customer data, or the installation of ransomware.

Technical details

A Remote Code Execution (RCE) vulnerability exists in the Cost Calculator Builder PRO plugin for WordPress (versions up to 4.0.3) within the js_to_php() function. The root cause is the insufficient sanitization of the 'orderDetails[*].originalValue' field, which is injected directly into a formula string passed to the PHP eval() function. While the evaluateFormula() function employs a regex allow-list, it only filters alphanumeric tokens, allowing non-word punctuation characters to remain. Attackers can bypass these restrictions using non-word XOR gadgets. Although a nonce check is present, the required nonce is publicly accessible via the wp_head hook, allowing unauthenticated attackers to achieve full code execution.

Affected products

  • StylemixThemes Cost Calculator Builder PRO 0 - 4.0.3

Timeline

  • 2026-07-29: disclosed: Vulnerability published by Wordfence and NVD

References