Vulnerabilities
Vulnerable Software
Credova:  >> Financial  >> 1.0.1  Security Vulnerabilities
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-09-29


Contact Us

Shodan ® - All rights reserved