---
id: CVE-2026-96255
title: >-
  The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public
  access to a debug log in which it records payment requests, including the
  store's payment gateway API credentials in plain text, allowing
  unauthenticated attac…
summary: >-
  The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public
  access to a debug log in which it records payment requests, including the
  store's payment gateway API credentials in plain text, allowing
  unauthenticated attac…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
product: Payments for Hubtel
affected:
  - payments_for_hubtel < 1.0.2
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T13:11:52.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96255'
references:
  - url: 'https://wpscan.com/vulnerability/726daec6-5e18-4ee1-9b97-3931f7f81c3c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-01T10:42:43.546597Z'
ingestedAt: '2026-10-01T06:38:44.656Z'
---

## Overview

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
