PT-2026-39974 · Qqqjus+1 · Slek Gateway For Woocommerce

·

CVE-2026-7626

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Slek Gateway for WooCommerce version 1.0
Description An information exposure issue exists where the wsb handle slek payment redirect() function places the merchant's slek key and slek secret API credentials directly into a client-side HTML form. Additionally, the slek secret is embedded as a plaintext GET parameter in the IPN (Instant Payment Notification) callback URL. Unauthenticated attackers who place an order can extract these credentials by inspecting the HTML source or using browser developer tools on the WooCommerce order-pay page before the JavaScript auto-submit executes.
Recommendations Update Slek Gateway for WooCommerce version 1.0 to a version that removes the exposure of API credentials in client-side forms and URLs.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7626

Affected Products

Slek Gateway For Woocommerce