Money Space <= 2.13.9 - Unauthenticated Sensitive Information Exposure
highThe MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the plugin storing full payment card details (PAN, card holder name, expiry month/year, and CVV) in WordPress post_meta using base64_encode(), and then embedding these values...
- CVSS:
- 8.6
- Affected:
- up to 2.13.9
- Fixed in:
- 2.14.0
- Disclosed:
- Jan 6, 2026