← Voltar à pesquisa de CVEs

CVE-2026-7626

Slek Gateway for WooCommerce

Descrição

The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_payment_redirect() function placing the merchant-s slek_key and slek_secret API credentials directly into a client-side HTML form, and additionally embedding the slek_secret as a plaintext GET parameter in the IPN callback URL. This makes it possible for unauthenticated attackers who can place an order on the affected store to extract the merchant-s API credentials by viewing the HTML source or using browser DevTools on the WooCommerce order-pay page before the JavaScript auto-submit fires.

CVSS 5.3EPSS 0.251%Risco 0.54
Ver fonte
Publicação
2026-05-12 09:16:57
Versões afetadas
==1.0
Tipo
Installed app
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N