CVE-2026-96255 PUBLISHED

Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log

Assigner: WPScan
Reserved: 22.09.2026 Published: 01.10.2026 Updated: 01.10.2026

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.

Product Status

Vendor Unknown
Product Payments for Hubtel
Versions Default: unaffected
  • affected from 0 to 1.0.2 (excl.)

Credits

  • Animesh Gaurav (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE