Description
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
No analysis available yet.
Remediation
Vendor Solution
Update to version 1.4.9, or newer.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25703 | The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8. |
References
History
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-31T18:11:47.779Z
Reserved: 2021-08-20T00:00:00.000Z
Link: CVE-2021-39342
Updated: 2024-08-04T02:06:42.322Z
Status : Modified
Published: 2021-09-29T20:15:08.543
Modified: 2024-11-21T06:19:21.330
Link: CVE-2021-39342
No data.
OpenCVE Enrichment
No data.
EUVD