Impact
The vulnerability exists in the Duitku Payment Gateway plugin for WordPress and allows an unauthenticated attacker to expose sensitive data. The plugin unlawfully stores or displays confidential information without proper authentication checks, leading to a loss of confidentiality. This weakness is classified as CWE‑497, which focuses on improper exposure of sensitive information.
Affected Systems
The issue affects all WordPress sites that have installed the Duitku Payment Gateway plugin version 2.11.14 or earlier. The plugin, produced by rayhanduitku, is commonly used in numerous e‑commerce WordPress installations, so any site running a vulnerable version is potentially exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and a high likelihood that the vulnerability could be leveraged. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, meaning there is no confirmed exploitation activity or cataloging of active attacks. Although the vulnerability is unauthenticated, it is inferred from the description that attackers do not require login credentials and that exploitation may occur via exposed configuration files, API callbacks, or faulty redirects that reveal sensitive credentials. The potential damage is primarily the theft of confidential transaction data, compromising user privacy and trust.
OpenCVE Enrichment