Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96173 | 1 Wordpress-extensions | 1 Payments For Hubtel | 2026-10-01 | 5.3 Medium |
| The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents. | ||||
| CVE-2026-96200 | 1 Wordpress-extensions | 1 Payments For Hubtel | 2026-10-01 | 5.3 Medium |
| The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | ||||
| CVE-2026-96255 | 1 Wordpress-extensions | 1 Payments For Hubtel | 2026-10-01 | 7.5 High |
| The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. | ||||
Page 1 of 1.