CVE-2026-49064: WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability
Published Jun 15, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.
This issue affects GetPaid: from n/a through 2.8.49.
Affected Software
1 affected component
Stiofan GetPaid<=2.8.49
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GetPaid Pluginto a version that resolves this vulnerability.Fixed in 2.8.50
Event History
Jun 15, 2026
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49064?
CVE-2026-49064 has a high severity rating of 7.5.
2
How do I fix CVE-2026-49064?
To fix CVE-2026-49064, update the GetPaid plugin to version 2.8.50 or later.
3
What type of vulnerability is CVE-2026-49064?
CVE-2026-49064 is an Insertion of Sensitive Information Into Sent Data vulnerability.
4
What software is affected by CVE-2026-49064?
CVE-2026-49064 affects the Stiofan GetPaid plugin versions up to 2.8.49.
5
What information is at risk due to CVE-2026-49064?
CVE-2026-49064 allows the retrieval of embedded sensitive data, leading to potential data exposure.