← Back to search

CVE-2026-7753

6.5 MEDIUM

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows authenticated attackers with Subscriber-level access or higher to export sensitive data, including secret keys for payment gateways and reCAPTCHA.
Exploitability
Exploitation is relatively easy as it requires only an authenticated session with Subscriber-level permissions or higher. Precondition: The attacker must have a valid WordPress account at the minimum Subscriber level.
Blast radius
If exploited, the impact could be significant, leading to data breaches and potential misuse of sensitive information like secret keys from payment gateways.
Prioritized remediation
Update to the latest version of the Cost Calculator Builder plugin, which addresses this vulnerability.
auth-bypassdata-exposureweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.