WordPress Plugin Vulnerabilities

Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure

Description

The plugin may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
WPScan Team
Submitter
WPScan Team
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-04-28 (about 1 month ago)
Added
2026-04-28 (about 1 month ago)
Last Updated
2026-04-28 (about 1 month ago)

Other