CVE-2026-96255: Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log
Published Oct 1, 2026
·Updated
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
Affected Software
1 affected component
Payments for Hubtel Payments for Hubtel<1.0.2
Event History
Oct 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote attacker can exploit it if the plugin's debug log is publicly accessible. No account or user interaction is required.
2
What information could be exposed?
The debug log records payment requests and may contain the store's payment gateway API credentials in plain text.
3
Which installations are affected?
Payments for Hubtel versions before 1.0.2 are affected when the debug log is publicly accessible.