Description
Insertion of Sensitive Information Into Sent Data vulnerability in Efí Bank Gerencianet Oficial woo-gerencianet-official allows Retrieve Embedded Sensitive Data.This issue affects Gerencianet Oficial: from n/a through <= 3.1.3.
Published: 2025-12-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Efí Bank Gerencianet Oficial WordPress plugin up to version 3.1.3 allows an attacker to retrieve sensitive information that is embedded in data sent by the plugin. The flaw was classified as a CWE-201-type insertion of sensitive information into transmitted data, resulting in a confidentiality breach for users whose transaction or login details are exposed.

Affected Systems

The affected product is the Gerencianet Oficial WooCommerce plugin distributed by Efí Bank. All releases from the earliest documented version through, and including, 3.1.3 are vulnerable; no specific patch level is listed in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, while an EPSS score of 1% suggests a low probability that the flaw will be actively exploited at present. The vulnerability is not part of the CISA KEV catalog. How the flaw is exploited is not described in the advisory, but the description implies that any user capable of interacting with the plugin – potentially even unauthenticated web requests – could trigger a response that contains the hidden sensitive data. The exact attack vector remains unconfirmed, but the disclosed behavior points to a data‑exfiltration risk that could be leveraged via the plugin’s API or normal usage pathways.

Generated by OpenCVE AI on April 29, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Gerencianet Oficial plugin to the latest available version once an official fix is released.
  • If an update is not immediately available, disable or remove the plugin to eliminate the exposure path.
  • Verify that sensitive data is not inadvertently included in any responses or logs generated by the plugin.

Generated by OpenCVE AI on April 29, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Efí Bank Gerencianet Oficial allows Retrieve Embedded Sensitive Data.This issue affects Gerencianet Oficial: from n/a through 3.1.3. Insertion of Sensitive Information Into Sent Data vulnerability in Efí Bank Gerencianet Oficial woo-gerencianet-official allows Retrieve Embedded Sensitive Data.This issue affects Gerencianet Oficial: from n/a through <= 3.1.3.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Efí Bank Gerencianet Oficial allows Retrieve Embedded Sensitive Data.This issue affects Gerencianet Oficial: from n/a through 3.1.3.
Title WordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:52.038Z

Reserved: 2025-09-09T14:47:17.697Z

Link: CVE-2025-59136

cve-icon Vulnrichment

Updated: 2025-12-31T16:51:16.812Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T16:15:43.580

Modified: 2026-04-23T15:34:02.857

Link: CVE-2025-59136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:00:07Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data