Junglewise Threat Intelligence

CVE-2026-52695: PayerURL ABC Crypto Checkout sensitive data exposure

CVE-2026-52695 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

ABC Crypto Checkout, a WordPress plugin used to process cryptocurrency payments for online stores, contains a security flaw that exposes sensitive information. An unauthorized person can access data that should be private, potentially revealing transaction details or configuration info. This could lead to further attacks on the website or compromise customer privacy.

Technical details

A sensitive data exposure vulnerability exists in the ABC Crypto Checkout plugin (<= 1.8.2) for WordPress, classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). The flaw allows an unauthenticated remote attacker to access sensitive information due to improper data handling within the plugin's components. With a CVSS score of 7.5, the attack vector is network-based with low complexity and requires no user interaction or privileges. This exposure could provide attackers with the necessary information to launch more sophisticated subsequent attacks. The issue is resolved in version 1.8.3.

Affected products

  • PayerURL ABC Crypto Checkout <= 1.8.2

Timeline

  • 2026-05-18: other: Vulnerability reported by researcher xwii
  • 2026-06-10: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published in NVD
  • 2026-06-10: patched: Fixed in version 1.8.3

References