CVE-2026-96173
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 01, 2026
Vendor
unknown
Description
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.