WordPress Plugin Vulnerabilities

Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR

Description

The plugin does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.

Proof of Concept

Affects Plugins

Fixed in 1.0.2

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other