Arbitrary File Deletion Vulnerability in Cost Calculator Builder Plugin for WordPress
CVE-2025-12529
What is CVE-2025-12529?
The Cost Calculator Builder plugin for WordPress is susceptible to arbitrary file deletion due to inadequate validation of file paths in the deleteOrdersFiles() functionality. This vulnerability allows unauthenticated users to manipulate the orders deletion process by injecting arbitrary file paths. The issue is present across all versions up to and including 3.6.3. An attacker could exploit this weakness to delete critical files, potentially leading to remote code execution, especially if a sensitive file such as wp-config.php is compromised. The vulnerability necessitates that both the free and Pro versions of the Cost Calculator Builder plugin are installed to be exploitable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cost Calculator Builder * <= 3.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved