ZeroHour

CVE-2025-15609

CVSS 3.1
7.5 high
EPSS
<1%p34
Published
()
Modified
Description

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.