The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2021-09-29T19:39:49.124356Z
Updated: 2024-09-16T20:17:08.439Z
Reserved: 2021-08-20T00:00:00
Link: CVE-2021-39342
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-29T20:15:08.543
Modified: 2024-11-21T06:19:21.330
Link: CVE-2021-39342
Redhat
No data.