Cost Calculator Builder PRO WordPress Plugin Vulnerable to RCE
The Cost Calculator Builder PRO plugin for WordPress appears to be vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3.
What happened
The Cost Calculator Builder PRO plugin for WordPress is under investigation for a critical vulnerability that could allow unauthenticated remote code execution. This is reportedly due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval(). The vulnerability affects all versions up to, and including, 4.0.3.
To assess your exposure, check if you are using the Cost Calculator Builder PRO plugin for WordPress version 4.0.3 or earlier. If so, it is recommended to upgrade to a version beyond 4.0.3 or apply a patch if available. Additionally, review your server logs for any suspicious activity that may indicate exploitation of this vulnerability.
The primary source for this vulnerability is CVE-2026-14900, which has a CVSS score of 9.8, indicating a critical severity. For more detailed information, consult the NVD page for CVE-2026-14900.
How 0Day mitigates this
cost calculator builder pro is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.