Junglewise Threat Intelligence

CVE-2026-49066: Conekta Payment Gateway sensitive data exposure

CVE-2026-49066 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

The Conekta Payment Gateway plugin for WordPress, which facilitates online payments, contains a security flaw that allows unauthorized individuals to access sensitive system information. An attacker could exploit this to view data that is normally restricted, potentially leading to further attacks on the website or its users. Business operations may be impacted if sensitive configuration or customer-related data is exposed.

Technical details

The Conekta Payment Gateway plugin for WordPress (versions <= 6.0.0) is vulnerable to sensitive data exposure (CWE-497). The vulnerability allows an unauthenticated remote attacker to access sensitive system information due to improper access controls or exposure of internal data to an unauthorized control sphere. This is a network-based attack with low complexity and requires no user interaction. The exposure can provide attackers with the necessary information to facilitate more complex subsequent attacks. A fix is available in version 6.0.1.

Affected products

  • Conekta Conekta Payment Gateway <= 6.0.0

Timeline

  • 2026-06-02: other: Reported by researcher dodoh4t
  • 2026-06-08: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published in NVD
  • 2026-06-08: patched: Version 6.0.1 released to address the vulnerability

References

Related threats