CVE-2021-39342 MEDIUM

CVE-2021-39342: Credova_Financial <= 1.4.8 Sensitive Information Disclosure

Vendor Credova Financial
Product Credova_Financial
Weakness CWE-319 · Cleartext transmission
Published September 29, 2021
Last update March 31, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.

Explanation of Vulnerability in Simple Terms

02Summary

Credova Financial version 1.4.8 transmits sensitive data over unencrypted connections. An attacker on the network path between a user and the application can intercept and read this data. No authentication or user interaction is required for the attacker to perform the interception.

What an attacker can do

03Attacker Capabilities

Intercept and read sensitive data transmitted by the application over the network.

Potential impact on your site

04Site Impact

User data and credentials transmitted through this application can be exposed to network eavesdropping.

Conditions required to exploit

05Prerequisites

Network access to the communication path between user and application; no authentication required.

Key dates

06Disclosure timeline

September 29, 2021 CVE published
March 31, 2025 Record updated