OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96255

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Payments for Hubtel WordPress plugin prior to version 1.0.2 exposes a debug log that contains sensitive payment gateway API credentials in plaintext, allowing unauthenticated attackers to access this information. This vulnerability poses a significant risk to online stores using the plugin, as it can lead to unauthorized transactions and data breaches. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-96255
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.