Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pgf-j495-ffj6

Опубликовано: 17 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

EPSS

Процентиль: 13%
0.00222
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.9
nvd
2 дня назад

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

EPSS

Процентиль: 13%
0.00222
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284