Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-97307 represents a critical data exposure vulnerability in the StylemixThemes Cost Calculator Builder WordPress plugin affecting versions up to 4.0.17. The vulnerability allows attackers to retrieve embedded sensitive information through the plugin's sent data handling mechanisms, exposing a CWE-201 weakness where sensitive data is inadvertently inserted into communications. This affects WordPress site operators using this popular e-commerce calculator tool, particularly those handling customer quotes, pricing data, and potentially personal information through the calculator's functionality. The high CVSS score of 7.5 reflects the significant risk of unauthorized data disclosure without requiring authentication or user interaction.
While this CVE does not map directly to MITRE ATT&CK techniques, Casky's Claude-powered analysis framework would detect the underlying attack patterns associated with data exfiltration and reconnaissance activities. Practitioners using Casky would observe detection signatures aligned with techniques like T1041 (Exfiltration Over C2 Channel) and T1020 (Automated Exfiltration), as the vulnerability mechanism involves unintended data transmission in plugin responses. Security teams would identify suspicious patterns in HTTP traffic where calculator-related requests contain embedded sensitive data in response payloads, cross-site data leakage indicators, and anomalous information flows between the WordPress frontend and backend. Extended reasoning analysis would flag the root cause as improper data sanitization in the builder's output functions, enabling practitioners to prioritize immediate patching to versions 4.0.18+ and implement input/output validation controls.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-97307. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation