{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cost-calculator-builder-pro-plugin--4.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-14900"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cost Calculator Builder PRO plugin (\u003c= 4.0.3)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","rce","web-exploitation","cve"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability, tracked as CVE-2026-14900, affects all versions up to and including 4.0.3 of the Cost Calculator Builder PRO plugin for WordPress. This flaw stems from inadequate sanitization of the \u003ccode\u003eorderDetails[*].originalValue\u003c/code\u003e field, which is directly injected into a calculator formula string passed to \u003ccode\u003ePHP eval()\u003c/code\u003e within the plugin's \u003ccode\u003ejs_to_php\u003c/code\u003e function. The plugin's \u003ccode\u003eevaluateFormula()\u003c/code\u003e function's regex allow-list only filters alphanumeric tokens, leaving non-word punctuation characters intact, thus enabling arbitrary code injection. While a nonce check is present, the required nonce is publicly exposed on every front-end page via the \u003ccode\u003ewp_head\u003c/code\u003e hook, making it easily obtainable by unauthenticated attackers. Successful exploitation allows an attacker to execute code on the server, potentially leading to full system compromise, data exfiltration, or website defacement. Organizations using this plugin are urged to patch immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker accesses any front-end page of a WordPress site running the vulnerable Cost Calculator Builder PRO plugin to retrieve the publicly emitted nonce.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious payload, embedding PHP code within the \u003ccode\u003eorderDetails[*].originalValue\u003c/code\u003e field, leveraging non-word punctuation characters or XOR gadgets to bypass existing sanitization mechanisms.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a specially crafted HTTP POST request to a vulnerable endpoint within the Cost Calculator Builder PRO plugin, including the stolen nonce and the malicious \u003ccode\u003eorderDetails[*].originalValue\u003c/code\u003e payload.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ejs_to_php\u003c/code\u003e function within the plugin receives and processes the incoming request, including the unsanitized \u003ccode\u003eorderDetails[*].originalValue\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe malicious payload, now part of a formula string, is passed to the \u003ccode\u003ePHP eval()\u003c/code\u003e function for execution.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eeval()\u003c/code\u003e function executes the attacker's injected PHP code on the underlying web server.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves unauthenticated Remote Code Execution (RCE), gaining control over the compromised WordPress instance and potentially the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14900 grants unauthenticated attackers remote code execution capabilities on the affected WordPress server. This level of access can lead to a complete compromise of the website, including data theft, defacement, injection of malicious content, and establishing persistence for further attacks. Attackers can leverage the compromised server as a platform for lateral movement within the network or to launch attacks against other systems. Organizations using this plugin could face significant operational disruption, reputational damage, and regulatory penalties due to data breaches. The CVSS v3.1 base score of 9.8 indicates critical severity and ease of exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Cost Calculator Builder PRO plugin to a patched version beyond 4.0.3 to mitigate CVE-2026-14900.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-14900 Exploitation - Cost Calculator Builder PRO RCE Attempt\u0026quot; to your SIEM system to detect attempted exploitation of this vulnerability.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive \u003ccode\u003ewebserver\u003c/code\u003e logging for all WordPress instances, focusing on HTTP POST requests, URI query parameters, and server response codes to aid in forensic analysis and detection.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003eprocess_creation\u003c/code\u003e logs on web servers for unusual child processes spawned by the web server user (e.g., \u003ccode\u003ephp-fpm\u003c/code\u003e, \u003ccode\u003eapache\u003c/code\u003e, \u003ccode\u003enginx\u003c/code\u003e) that could indicate successful RCE.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T11:19:28Z","date_published":"2026-07-29T11:19:28Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cost-calculator-rce/","summary":"The Cost Calculator Builder PRO plugin for WordPress, versions up to and including 4.0.3, is vulnerable to unauthenticated Remote Code Execution (RCE) via CVE-2026-14900 due to insufficient sanitization of the `orderDetails[*].originalValue` field, allowing arbitrary code injection into a `PHP eval()` call that can be exploited by unauthenticated attackers.","title":"Remote Code Execution in Cost Calculator Builder PRO WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-cost-calculator-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cost Calculator Builder PRO Plugin (\u003c= 4.0.3)","version":"https://jsonfeed.org/version/1.1"}