Arbitrary File Deletion Vulnerability in Cost Calculator Builder Plugin for WordPress
CVE-2025-12529
8.8HIGH
What is CVE-2025-12529?
The Cost Calculator Builder plugin for WordPress is susceptible to arbitrary file deletion due to inadequate validation of file paths in the deleteOrdersFiles() functionality. This vulnerability allows unauthenticated users to manipulate the orders deletion process by injecting arbitrary file paths. The issue is present across all versions up to and including 3.6.3. An attacker could exploit this weakness to delete critical files, potentially leading to remote code execution, especially if a sensitive file such as wp-config.php is compromised. The vulnerability necessitates that both the free and Pro versions of the Cost Calculator Builder plugin are installed to be exploitable.
Affected Version(s)
Cost Calculator Builder * <= 3.6.3