CVE 7.5 HIGH

Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure_CVE-2025-15609

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

Basic Information

ID CVE-2025-15609
Source WPScan
Published May 19, 2026 at 06:00
Modified May 19, 2026 at 13:16

Affected Product

Vendor Unknown
Product Fortis for WooCommerce
Affected Versions Unknown Fortis for WooCommerce 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.