Description
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the complete() function only verifying a nonce without checking user capabilities or order ownership. Since nonces are exposed to all visitors via window.ccb_nonces in the page source, any unauthenticated attacker can mark any order's payment status as "completed" without actual payment.
INFO
Published Date :
2026-01-16T08:38:29.508Z
Last Modified :
2026-01-16T13:04:53.115Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2025-14757 vulnerability.
| Vendors | Products |
|---|---|
| Stylemixthemes |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-14757.