Vulnerabilities > Credova
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-29 | CVE-2021-39342 | Insufficiently Protected Credentials vulnerability in Credova Financial The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. | 7.5 |