Junglewise Threat Intelligence

CVE-2026-49064: Stiofan GetPaid sensitive data exposure

CVE-2026-49064 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

The GetPaid plugin for WordPress, which is used for processing payments and invoicing, contains a security flaw that exposes sensitive information. An unauthorized person could access data that should be private, potentially leading to the exposure of customer or transaction details. This information could be used to facilitate further attacks or compromise business operations.

Technical details

A sensitive data exposure vulnerability (CWE-201) exists in the Stiofan GetPaid plugin for WordPress through version 2.8.49. The root cause is the insertion of sensitive information into data sent by the application, which allows unauthenticated remote attackers to retrieve embedded sensitive data. The attack can be carried out over the network without any user interaction or special privileges. This could lead to the disclosure of internal system details or user-related data. The issue is resolved in version 2.8.50.

Affected products

  • Stiofan GetPaid <= 2.8.49

Timeline

  • 2026-06-04: other: Reported by researcher Ananda Dhakal
  • 2026-06-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: CVE published to NVD
  • 2026-06-15: patched: Patch available in version 2.8.50

References

Related threats