Executive brief
The Duitku Payment Gateway is a WordPress plugin that processes payments for online stores. An unauthenticated attacker can expose sensitive data including customer passwords, email addresses, and payment details without any authentication, putting customer accounts and financial information at risk.
Technical details
This is a sensitive data exposure vulnerability in the Duitku Payment Gateway WordPress plugin (versions <= 2.11.14) that allows unauthenticated attackers to access private information. The vulnerability does not require user authentication to exploit, making it highly accessible to remote attackers over the network. Successful exploitation exposes customer passwords, email addresses, and payment card details. As of the advisory date, no official patch is available from the vendor; Patchstack has issued a mitigation rule to block exploit attempts.
Affected products
- Duitku Payment Gateway <= 2.11.14
Timeline
- 2026-08-18: disclosed
- 2026-01-21: advisory: Reported by daroo