Description
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Credentials Disclosure
Action: Apply Update
AI Analysis

Impact

The Vulnerability permits unauthenticated access to a publicly visible debug log that contains plain‑text payment gateway API credentials. An attacker who retrieves this log can acquire the credentials and exploit the store’s payment system for fraudulent transactions, potentially leading to financial loss and a breach of customer data. The lack of authentication control results in direct credentials disclosure (CWE‑200).

Affected Systems

The issue affects the Payments for Hubtel WordPress plugin for all versions earlier than 1.0.2. Any WordPress website using this plugin in those versions is vulnerable.

Risk and Exploitability

Exploitation requires only the ability to request the log file via the web server; no privileged access or specialized tools are necessary. While the CVSS score is not provided and EPSS is unavailable, the nature of the credential leakage represents a severe risk. The vulnerability is not listed in CISA KEV, but given the potential impact, administrators should consider it high risk and remediate promptly.

Generated by OpenCVE AI on October 1, 2026 at 07:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Payments for Hubtel plugin to version 1.0.2 or later.
  • Disable debug logging or restrict access to the debug log so that it is not publicly accessible.
  • Verify that the plugin no longer records or stores API credentials in plain text.

Generated by OpenCVE AI on October 1, 2026 at 07:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 01 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
Title Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-01T10:45:48.394Z

Reserved: 2026-09-22T19:08:36.495Z

Link: CVE-2026-96255

cve-icon Vulnrichment

Updated: 2026-10-01T10:42:34.621Z

cve-icon NVD

Status : Received

Published: 2026-10-01T06:17:16.460

Modified: 2026-10-01T11:17:30.660

Link: CVE-2026-96255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor