← WordPress Vulnerabilities
WordPress security by component

Payments for Hubtel

Payments for Hubtel (payments-for-hubtel) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: payments-for-hubtel

CVE-2026-96255: Payments for Hubtel: Public debug log exposes payment gateway credentials

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. The authoritative export identifies the fixed release as 1.0.2.

PublishedOct 01, 2026
Known safe version1.0.2
Published vulnerabilities for payments-for-hubtel
Safe version
Oct 01, 2026 CVE-2026-96255
Payments for Hubtel: Public debug log exposes payment gateway credentials
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. The authoritative export identifies the fixed release as 1.0.2.
1.0.2
CVEPending
NVDPending
Oct 01, 2026 CVE-2026-96200
Payments for Hubtel: Broken access control
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.0.2.
1.0.2
CVEPending
NVDPending
Oct 01, 2026 CVE-2026-96173
Payments for Hubtel: Public payment callback exposes order keys and contents
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.0.2.
1.0.2
CVEPending
NVDPending