CVE-2025-39587

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 89

Summary

CVE-2025-39587 is an SQL Injection vulnerability affecting the Stylemix Cost Calculator Builder. Hackers can exploit this issue by introducing malicious SQL commands, which could result in unauthorized access to sensitive data or even system takeover. Affected versions of the Cost Calculator Builder include those from the initial release through 3.2.65. Organizations using this software are advised to apply the necessary patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cost Calculator Builder Plugin

Affected Vendors

  • WordPress