PT-2026-5887 · WordPress+1 · Chapa Payment Gateway Plugin For Woocommerce+1

Published

2026-02-04

·

Updated

2026-02-04

·

CVE-2025-15482

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chapa Payment Gateway Plugin for WooCommerce versions up to and including 1.0.3
Description The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is susceptible to sensitive information disclosure. An unauthenticated attacker can extract sensitive data, including the merchant's Chapa secret API key, through the 'chapa proceed' API endpoint. The chapa proceed endpoint is the point of access for this issue.
Recommendations Update the Chapa Payment Gateway Plugin for WooCommerce to a version later than 1.0.3.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-15482

Affected Products

Chapa Payment Gateway Plugin For Woocommerce
Woocommerce