What is CVE-2026-14900?
The Cost Calculator Builder PRO plugin for WordPress (versions up to and including 4.0.3) is vulnerable to Remote Code Execution via the `js_to_php` function due to insufficient sanitization of the `orderDetails[*].originalValue` field, which is injected verbatim into a calculator formula. Users should urgently update the plugin to the latest patched version to mitigate this critical risk.
Azərbaycanca: WordPress üçün Cost Calculator Builder PRO plaqininin 4.0.3 daxil olmaqla bütün versiyalarında `js_to_php` funksiyası vasitəsilə Remote Code Execution zəifliyi aşkarlanıb. `orderDetails[*].originalValue` sahəsinin kifayət qədər təmizlənməməsi səbəbindən təcavüzkar kalkulyator formulu vasitəsilə serverdə kod icra edə bilər. İstifadəçilərə dərhal plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Through which function is the CVE-2026-14900 vulnerability exploited in the Cost Calculator Builder PRO plugin?
The vulnerability is exploited through the plugin's `js_to_php` function.
What is recommended for users to protect against CVE-2026-14900?
Users are recommended to urgently update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.