PT-2021-22549 · WordPress · Credova Financial

Marvin Santos

·

Published

2021-09-29

·

Updated

2022-08-05

·

CVE-2021-39342

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Credova Financial WordPress plugin versions up to, and including, 1.4.8
Description: The Credova Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled.
Recommendations: For versions up to, and including, 1.4.8, update to a version later than 1.4.8 to resolve the issue. As a temporary workaround, consider disabling the Credova Financing option on checkout pages until a patch is available. Restrict access to the AJAX action that discloses the Credova API account credentials to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39342

Affected Products

Credova Financial