Vulnerabilities > Credova

DATE CVE VULNERABILITY TITLE RISK
2021-09-29 CVE-2021-39342 Insufficiently Protected Credentials vulnerability in Credova Financial
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled.
network
low complexity
credova CWE-522
7.5