CVE-2026-96173 PUBLISHED

Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR

Assigner: WPScan
Reserved: 22.09.2026 Published: 01.10.2026 Updated: 01.10.2026

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.

Product Status

Vendor Unknown
Product Payments for Hubtel
Versions Default: unaffected
  • affected from 0 to 1.0.2 (excl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE