WordPress security by component
handily
handily is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 22, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
handilyLatest vulnerability
CVE-2025-14487: Handily exposes Stripe payment settings to anonymous modification
An unauthenticated attacker can change Stripe publishable/secret keys, payment email addresses and success/cancel URLs through payment-setting inputs without authorization. Replacing the payment configuration can divert subsequent payments to an attacker-controlled Stripe account. The endpoint and exact parameter names are unspecified; disclosure of the previous secret key is not established. Affected versions: <= 1.0.3. No fixed release is confirmed in this review.
| Safe version |
|
||
|---|---|---|---|
| Sep 22, 2026 |
CVE-2025-14487
Handily exposes Stripe payment settings to anonymous modification
An unauthenticated attacker can change Stripe publishable/secret keys, payment email addresses and success/cancel URLs through payment-setting inputs without authorization. Replacing the payment configuration can divert subsequent payments to an attacker-controlled Stripe account. The endpoint and exact parameter names are unspecified; disclosure of the previous secret key is not established. Affected versions: <= 1.0.3. No fixed release is confirmed in this review.
|
See mitigation notes |
CVE5.3
NVDPending
|