Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91019

Опубликовано: 17 сент. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

EPSS

Процентиль: 13%
0.00222
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.9
github
2 дня назад

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.

EPSS

Процентиль: 13%
0.00222
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284