PT-2026-41827 · Woocommerce · Fortios
Wpscan Team
·
Published
2026-05-19
·
Updated
2026-05-19
·
CVE-2025-15609
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fortis for WooCommerce versions prior to 1.3.1
Description
The Fortis for WooCommerce WordPress plugin may leak sensitive API keys to unauthenticated attackers. This exposure allows attackers to query the Fortis API and retrieve sensitive customer information, including personally identifiable information (PII) and past order details.
Recommendations
Update to version 1.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios