Description
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Order Data
Action: Patch Immediately
AI Analysis

Impact

The Payments for Hubtel plugin for WordPress allows an unauthenticated attacker to request the public payment-callback endpoint without confirming that the requester is authorized to view that particular order. As a result, the system leaks the order key, which reveals all details of any order. This leads to exposure of potentially sensitive financial information and confirms an IDOR flaw.

Affected Systems

The vulnerability affects all deployments of the Payments for Hubtel plugin before version 1.0.2 on WordPress sites. The plugin uses an order key that is intended to be protected but is accessible to anyone who can send a public request, meaning that any compromised or even guessed order URL exposes the full contents to an unauthenticated party.

Risk and Exploitability

The flaw is exploitable over the public internet via the payment-callback URL, requiring no authentication. While an official CVSS score is not provided, the vulnerability enables unauthorized disclosure of order contents. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV. An attacker could retrieve the order key by sending a request to any order identifier.

Generated by OpenCVE AI on October 1, 2026 at 08:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Payments for Hubtel to version 1.0.2 or later.
  • Restrict public access to the payment-callback endpoint by requiring authentication or using firewall rules.
  • Scan your WordPress installation for other outdated or vulnerable plugins and remove them.

Generated by OpenCVE AI on October 1, 2026 at 08:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-639

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.
Title Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:48.667Z

Reserved: 2026-09-22T18:45:24.048Z

Link: CVE-2026-96173

cve-icon Vulnrichment

Updated: 2026-10-01T10:42:53.605Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:15.763

Modified: 2026-10-01T11:17:30.293

Link: CVE-2026-96173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-639

    Authorization Bypass Through User-Controlled Key