Sceawere
Vulnerability Detail
CVE-2026-66444UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Paystack Payment Forms Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 7h ago
- Vendor
- kendysond
- Product
- Payment Forms for Paystack
- Attack Type
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-13T14:17:05.763Z",
"pubdate": "2026-08-13T14:17:05.763Z",
"executiveSummary": "A subscriber sensitive data exposure vulnerability has been identified in the Paystack plugin <= 4.0.5 versions. This security flaw involves the improper handling and exposure of sensitive subscriber information directly within payment forms rendered by the application.\nThe primary impact of this vulnerability is the unauthorized disclosure of confidential user data, which may include personally identifiable information (PII) or financial transaction metadata. Such data leakage compromises user privacy and exposes affected individuals to downstream risks such as targeted phishing, social engineering, or secondary credential harvesting.\nThe affected system is the Paystack payment integration module for versions up to 4.0.5. The risk implications are moderate to high depending on the specific data points exposed during the form rendering process. Attackers do not necessarily require complex privileges to harvest this information if the data is rendered insecurely within the DOM or HTTP responses accessible to unauthorized observers.\nExploitation requirements typically involve interacting with or inspecting the vulnerable payment forms where the sensitive subscriber data is improperly exposed. Remediation requires updating the affected product to a secure version once available or applying vendor-supplied patches to restrict data exposure.",
"technicalDetails": "The vulnerability stems from the insecure handling and rendering of subscriber sensitive data within payment forms implemented by Paystack <= 4.0.5. The root cause lies in the application logic failing to properly sanitize, restrict, or mask sensitive fields before sending them to the client-side interface or including them within the Document Object Model (DOM) of the payment form.\nThe vulnerable component resides within the payment form generation and rendering functions of the Paystack plugin. Affected versions include all iterations up to and including version 4.0.5. The exposure occurs over standard network exposure vectors where the payment forms are accessible, potentially allowing unauthenticated or low-privileged actors to observe sensitive payloads.\nThe attack flow proceeds as follows: First, an end-user or attacker navigates to a page containing the vulnerable Paystack payment form. Second, the application processes the subscriber data and injects it into the form markup or transmits it via unencrypted or overly verbose client-side scripts. Third, because the sensitive data is exposed in the DOM or HTTP response, an observer or script can harvest the exposed parameters without triggering standard authorization barriers.\nPost-exploitation impact includes the aggregation of sensitive subscriber details, which can be leveraged for further compromise, identity theft, or unauthorized tracking of financial transactions processed through the vulnerable payment gateway implementation."
}