CVE-2025-15482 PUBLISHED

Chapa Payment Gateway Plugin for WooCommerce <= 1.0.3 - Unauthenticated Sensitive Information Exposure

Assigner: Wordfence
Reserved: 07.01.2026 Published: 04.02.2026 Updated: 04.02.2026

The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 via 'chapa_proceed' WooCommerce API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including the merchant's Chapa secret API key.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor chapaet
Product Chapa Payment Gateway Plugin for WooCommerce
Versions Default: unaffected
  • affected from * to 1.0.3 (incl.)

Credits

  • Md. Moniruzzaman Prodhan finder

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE