What is CVE-2026-7753?
The Cost Calculator Builder plugin for WordPress (versions up to and including 3.6.17) is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action, allowing unauthenticated users to access sensitive information. Updating to the latest plugin version is recommended.
Azərbaycanca: WordPress üçün Cost Calculator Builder plaginində (3.6.17-yə qədər versiyalar) `cost-calculator-custom-export-run` AJAX funksiyasında icazə yoxlanışının (`capability check`) olmaması səbəbindən autentifikasiya olunmamış istifadəçilər həssas məlumatlara icazəsiz giriş əldə edə bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-7753?
The vulnerability affects the Cost Calculator Builder plugin, specifically versions up to and including 3.6.17.
Is authentication required to exploit this vulnerability?
No, due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action, unauthenticated users can gain unauthorized access to sensitive data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.