LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-15609

Published
CVSS7.5
Severityhigh
Weakness—
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-15609

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-15609.