CVE-2026-96255

NONE
Updated Oct 01, 2026
WordPress
Parameter Value
Affected Versions before 1.0.2
Type CWE-200 Information Exposure
Vendor WordPress
Public PoC No

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.

Weakness Type (CWE)

Vulnerable Products

unknown:payments for hubtel