← WordPress Vulnerabilities
WordPress security by component

handily

handily is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 22, 2026; the highest published CVSS base score is 5.3.

Plugin slug: handily

CVE-2025-14487: Handily exposes Stripe payment settings to anonymous modification

An unauthenticated attacker can change Stripe publishable/secret keys, payment email addresses and success/cancel URLs through payment-setting inputs without authorization. Replacing the payment configuration can divert subsequent payments to an attacker-controlled Stripe account. The endpoint and exact parameter names are unspecified; disclosure of the previous secret key is not established. Affected versions: <= 1.0.3. No fixed release is confirmed in this review.

PublishedSep 22, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for handily
Safe version
Sep 22, 2026 CVE-2025-14487
Handily exposes Stripe payment settings to anonymous modification
An unauthenticated attacker can change Stripe publishable/secret keys, payment email addresses and success/cancel URLs through payment-setting inputs without authorization. Replacing the payment configuration can divert subsequent payments to an attacker-controlled Stripe account. The endpoint and exact parameter names are unspecified; disclosure of the previous secret key is not established. Affected versions: <= 1.0.3. No fixed release is confirmed in this review.
See mitigation notes
CVE5.3
NVDPending