Impact
The Payments for Hubtel plugin for WordPress allows an unauthenticated attacker to request the public payment-callback endpoint without confirming that the requester is authorized to view that particular order. As a result, the system leaks the order key, which reveals all details of any order. This leads to exposure of potentially sensitive financial information and confirms an IDOR flaw.
Affected Systems
The vulnerability affects all deployments of the Payments for Hubtel plugin before version 1.0.2 on WordPress sites. The plugin uses an order key that is intended to be protected but is accessible to anyone who can send a public request, meaning that any compromised or even guessed order URL exposes the full contents to an unauthenticated party.
Risk and Exploitability
The flaw is exploitable over the public internet via the payment-callback URL, requiring no authentication. While an official CVSS score is not provided, the vulnerability enables unauthorized disclosure of order contents. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV. An attacker could retrieve the order key by sending a request to any order identifier.
OpenCVE Enrichment