PoC Index

CVE-2025-15609

HIGH 7.5EPSS 0.4%

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.40% chance of exploitation in the next 30 days, 34th percentile
Published
2026-05-19

Proof-of-concept exploits (1)

References

Related