Impact
Insertion of Sensitive Information Into Sent Data allows attackers to retrieve embedded sensitive data transmitted by the Tabby Checkout plugin. The flaw arises from improper handling of confidential information during data transmission, resulting in exposure of private data such as payment details or user credentials. The impact is loss of confidentiality and possible downstream misuse of the captured data, potentially leading to financial loss or identity compromise.
Affected Systems
The vulnerability affects the Tabby Checkout WordPress plugin from the earliest release through version 5.8.4. Any WordPress site using Tabby Checkout up to and including 5.8.4 is impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Although detailed exploitation steps are not provided in the description, the plugin’s web-based nature suggests an attacker could send crafted requests to the plugin’s endpoints and capture the improperly protected data. Given the high confidentiality risk, patching remains the critical mitigation.
OpenCVE Enrichment