Description
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability affects versions of the Payment Forms for Paystack WordPress plugin up to 4.0.5 and allows an attacker to read subscriber sensitive data that should be protected. The weakness enables the exfiltration of personal information such as payment details or personal identifiers that are stored or displayed by the plugin. Consequently, confidentiality of subscriber information is compromised, potentially leading to identity theft or fraud.

Affected Systems

WordPress sites using the kendysond Payment Forms for Paystack plugin with versions 4.0.5 or earlier.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need access to the plugin’s administrative interface or other authorized site functions to leverage the data exposure flaw; the attack vector is inferred because it is not explicitly detailed in the CVE description.

Generated by OpenCVE AI on August 13, 2026 at 15:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Payment Forms for Paystack plugin to version 4.0.6 or later.
  • Restrict access to subscriber data within the plugin’s settings so that only users with appropriate administrative roles can view it.
  • Audit current usage of the plugin to confirm that no sensitive data is inadvertently displayed or logged, and adjust configuration accordingly.

Generated by OpenCVE AI on August 13, 2026 at 15:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Title WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:27:15.486Z

Reserved: 2026-07-27T09:00:28.156Z

Link: CVE-2026-66444

cve-icon Vulnrichment

Updated: 2026-08-13T15:27:10.304Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:05.763

Modified: 2026-08-13T16:18:43.357

Link: CVE-2026-66444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:11Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere