API Key Exposure in Fortis Plugin for WooCommerce by Fortis Technologies
CVE-2025-15609
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 May 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2025-15609?
The Fortis for WooCommerce plugin, prior to version 1.3.1, has a vulnerability that allows unauthenticated attackers to access sensitive API keys. This flaw enables them to query the Fortis API, potentially exposing sensitive customer data, including past orders and personally identifiable information (PII). It is crucial for users to update to the latest version to mitigate the risk of data breaches.
Affected Version(s)
Fortis for WooCommerce 0 < 1.3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.