CVE-2026-96255
Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
| Vendor | unknown |
| Product | payments for hubtel |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown payments for hubtel
Be the first to know when new unknown vulnerabilities affecting unknown payments for hubtel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Payments for Hubtel
0 < 1.0.2
References
Credits
Animesh Gaurav (WPScan) WPScan