๐Ÿ” CVE Alert

CVE-2026-96173

UNKNOWN 0.0

Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.

Vendor unknown
Product payments for hubtel
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown payments for hubtel

Be the first to know when new unknown vulnerabilities affecting unknown payments for hubtel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Payments for Hubtel
0 < 1.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fcaa1526-0cf4-4356-9cf8-bc2dc3ed33b8/

Credits

Naoki Kawahigashi WPScan