CVE-2025-15482

The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 via 'chapa_proceed' WooCommerce API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including the merchant's Chapa secret API key.
Configurations

No configuration.

History

04 Feb 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 09:15

Updated : 2026-02-04 16:33


NVD link : CVE-2025-15482

Mitre link : CVE-2025-15482

CVE.ORG link : CVE-2025-15482


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor