What the vulnerability does
01Description
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
Explanation of Vulnerability in Simple Terms
02Summary
Credova Financial version 1.4.8 transmits sensitive data over unencrypted connections. An attacker on the network path between a user and the application can intercept and read this data. No authentication or user interaction is required for the attacker to perform the interception.
What an attacker can do
03Attacker Capabilities
Intercept and read sensitive data transmitted by the application over the network.
Potential impact on your site
04Site Impact
User data and credentials transmitted through this application can be exposed to network eavesdropping.
Conditions required to exploit
05Prerequisites
Network access to the communication path between user and application; no authentication required.
Key dates
06Disclosure timeline
September 29, 2021
CVE published
March 31, 2025
Record updated