Sensitive Data Exposure in Stiofan GetPaid Invoicing Plugin
CVE-2026-49064
7.5HIGH
What is CVE-2026-49064?
The Stiofan GetPaid invoicing plugin contains a vulnerability that allows the insertion of sensitive information into sent data. This flaw enables unauthorized retrieval of embedded sensitive data, putting user data and privacy at risk. Affected versions of the GetPaid plugin prior to 2.8.49 require urgent attention to mitigate potential information breaches.
Affected Version(s)
GetPaid <= 2.8.49