What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.
Explanation of Vulnerability in Simple Terms
WP Stripe Checkout versions up to 1.2.2.37 expose sensitive information in logs or error messages without proper access controls. An attacker on the network can read this data without authentication. The vulnerability affects confidentiality but not integrity or availability. Update to a version newer than 1.2.2.37.
What an attacker can do
Read sensitive information exposed in logs or error messages without logging in.
Potential impact on your site
Sensitive data (payment details, tokens, or credentials) may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities