Executive brief
The Direct Payments WP WordPress plugin contains a vulnerability that exposes sensitive system information to unauthorized parties. This allows attackers to retrieve embedded sensitive data such as payment details, credentials, or other private information stored by the plugin. An attacker with subscriber-level access can exploit this to steal sensitive information without requiring special privileges.
Technical details
This vulnerability is a sensitive data exposure flaw in the Direct Payments WP WordPress plugin that allows unauthorized retrieval of embedded sensitive data. The vulnerability requires subscriber-level privileges to exploit, indicating an authenticated access requirement. An attacker with a valid subscriber account can access private information such as payment details, emails, passwords, or other sensitive data managed by the plugin through an unprotected endpoint or inadequate access control checks. The vulnerability affects all versions up to and including 1.4.1, with no official patch currently available according to Patchstack. Remediation requires updating the plugin or disabling it until a patched version is released.
Affected products
- Digages Direct Payments WP <= 1.4.1
Timeline
- 2025-12-31: disclosed
- 2025-10-08: reported