Sensitive Data Exposure in Duitku Payment Gateway by Duitku
CVE-2026-32468

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-32468?

The Duitku Payment Gateway versions up to 2.11.14 are susceptible to an unauthenticated sensitive data exposure vulnerability that can potentially allow attackers to access sensitive information without proper authentication. This poses significant risks to user privacy and data integrity, emphasizing the need for organizations utilizing this payment gateway to upgrade to a secure version promptly.

Affected Version(s)

Duitku Payment Gateway <= 2.11.14

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.