Arbitrary File Deletion Vulnerability in Cost Calculator Builder Plugin for WordPress
CVE-2025-12529

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 December 2025

What is CVE-2025-12529?

The Cost Calculator Builder plugin for WordPress is susceptible to arbitrary file deletion due to inadequate validation of file paths in the deleteOrdersFiles() functionality. This vulnerability allows unauthenticated users to manipulate the orders deletion process by injecting arbitrary file paths. The issue is present across all versions up to and including 3.6.3. An attacker could exploit this weakness to delete critical files, potentially leading to remote code execution, especially if a sensitive file such as wp-config.php is compromised. The vulnerability necessitates that both the free and Pro versions of the Cost Calculator Builder plugin are installed to be exploitable.

Affected Version(s)

Cost Calculator Builder * <= 3.6.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JEONG YU CHAN
.