Executive brief
The Stylish Cost Calculator plugin for WordPress, which allows businesses to provide instant price quotes to customers, contains a security flaw that allows unauthorized individuals to access restricted data. An attacker could exploit this to view sensitive information that should only be available to site administrators. This could lead to the exposure of internal business data or customer information, potentially impacting the organization's reputation and data privacy compliance.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Stylish Cost Calculator plugin for WordPress in versions up to 8.3.9. The flaw stems from a lack of proper authorization checks, allowing an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is on confidentiality (High), suggesting an attacker can retrieve sensitive information from the site's backend without any prior authentication or user interaction. The issue is resolved in version 8.3.10.
Affected products
- Design Stylish Cost Calculator <= 8.3.9
Timeline
- 2026-06-06: other: Reported by ParkHyunWoo
- 2026-06-18: disclosed: Vulnerability disclosed by Patchstack
- 2026-06-26: advisory: NVD published CVE-2026-54847