Duitku Payment Gateway
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32468 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | ||
| CVE-2024-0631 | Med | 0.35 | 5.3 | 0.01 | Mar 13, 2024 | The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. This makes it possible for unauthenticated attackers to change… |
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
- risk 0.35cvss 5.3epss 0.01
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. This makes it possible for unauthenticated attackers to change…