CVE-2026-32468: WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Affected Software
1 affected component
WordPress Duitku Payment Gateway plugin<=2.11.14
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The issue is network-accessible and requires no authentication or user interaction. An unauthenticated remote attacker could exploit it.
2
Which versions are affected, and is a fixed version identified?
The affected versions are 2.11.14 and earlier. The provided data does not identify a fixed version or any workaround for deployments that cannot patch immediately.
3
What is the expected security impact?
The vulnerability is rated high with a CVSS score of 7.5. Its vector indicates high confidentiality impact, with no stated integrity or availability impact.