WordPress security by component
Payments for Hubtel
Payments for Hubtel (payments-for-hubtel) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
payments-for-hubtelLatest vulnerability
CVE-2026-96255: Payments for Hubtel: Public debug log exposes payment gateway credentials
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. The authoritative export identifies the fixed release as 1.0.2.
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-96255
Payments for Hubtel: Public debug log exposes payment gateway credentials
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. The authoritative export identifies the fixed release as 1.0.2.
|
1.0.2 |
CVEPending
NVDPending
|
| Oct 01, 2026 |
CVE-2026-96200
Payments for Hubtel: Broken access control
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.0.2.
|
1.0.2 |
CVEPending
NVDPending
|
| Oct 01, 2026 |
CVE-2026-96173
Payments for Hubtel: Public payment callback exposes order keys and contents
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents. The authoritative export does not name the request parameter or handler beyond the affected feature described above. The authoritative export identifies the fixed release as 1.0.2.
|
1.0.2 |
CVEPending
NVDPending
|