VYPR
Medium severity5.3NVD Advisory· Published Sep 13, 2023· Updated Apr 8, 2026

CVE-2023-4917

CVE-2023-4917

Description

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

Affected products

1
  • cpe:2.3:a:te-st:leyka:*:*:*:*:*:wordpress:*:*
    Range: <=3.30.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.