PT-2026-39974 · Qqqjus+1 · Slek Gateway For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Slek Gateway for WooCommerce version 1.0
Description
An information exposure issue exists where the
wsb handle slek payment redirect() function places the merchant's slek key and slek secret API credentials directly into a client-side HTML form. Additionally, the slek secret is embedded as a plaintext GET parameter in the IPN (Instant Payment Notification) callback URL. Unauthenticated attackers who place an order can extract these credentials by inspecting the HTML source or using browser developer tools on the WooCommerce order-pay page before the JavaScript auto-submit executes.Recommendations
Update Slek Gateway for WooCommerce version 1.0 to a version that removes the exposure of API credentials in client-side forms and URLs.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slek Gateway For Woocommerce