Description
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Duitku Payment Gateway plugin for WordPress and allows an unauthenticated attacker to expose sensitive data. The plugin unlawfully stores or displays confidential information without proper authentication checks, leading to a loss of confidentiality. This weakness is classified as CWE‑497, which focuses on improper exposure of sensitive information.

Affected Systems

The issue affects all WordPress sites that have installed the Duitku Payment Gateway plugin version 2.11.14 or earlier. The plugin, produced by rayhanduitku, is commonly used in numerous e‑commerce WordPress installations, so any site running a vulnerable version is potentially exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact and a high likelihood that the vulnerability could be leveraged. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, meaning there is no confirmed exploitation activity or cataloging of active attacks. Although the vulnerability is unauthenticated, it is inferred from the description that attackers do not require login credentials and that exploitation may occur via exposed configuration files, API callbacks, or faulty redirects that reveal sensitive credentials. The potential damage is primarily the theft of confidential transaction data, compromising user privacy and trust.

Generated by OpenCVE AI on August 18, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Duitku Payment Gateway plugin to the latest version (2.11.15 or newer) to receive the vendor patch that corrects the data exposure flaw.
  • Review the plugin’s configuration files and remove any hard‑coded or residual credentials that might have been left exposed by older versions.
  • Run a security scan on the WordPress installation to detect any remaining sensitive information that could still be accessible and remediate accordingly.

Generated by OpenCVE AI on August 18, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Duitku
Duitku duitku Payment Gateway
Wordpress
Wordpress wordpress
Vendors & Products Duitku
Duitku duitku Payment Gateway
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Title WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Duitku Duitku Payment Gateway
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:19:13.853Z

Reserved: 2026-03-12T11:11:50.221Z

Link: CVE-2026-32468

cve-icon Vulnrichment

Updated: 2026-08-18T14:18:57.176Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T14:17:05.857

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-32468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:12Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere