Impact
The Vulnerability permits unauthenticated access to a publicly visible debug log that contains plain‑text payment gateway API credentials. An attacker who retrieves this log can acquire the credentials and exploit the store’s payment system for fraudulent transactions, potentially leading to financial loss and a breach of customer data. The lack of authentication control results in direct credentials disclosure (CWE‑200).
Affected Systems
The issue affects the Payments for Hubtel WordPress plugin for all versions earlier than 1.0.2. Any WordPress website using this plugin in those versions is vulnerable.
Risk and Exploitability
Exploitation requires only the ability to request the log file via the web server; no privileged access or specialized tools are necessary. While the CVSS score is not provided and EPSS is unavailable, the nature of the credential leakage represents a severe risk. The vulnerability is not listed in CISA KEV, but given the potential impact, administrators should consider it high risk and remediate promptly.
OpenCVE Enrichment