
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15482 is a sensitive information exposure vulnerability in the Chapa Payment Gateway Plugin for WooCommerce for WordPress. It affects all versions up to and including 1.0.3, allowing unauthenticated attackers to extract sensitive data — most critically, the merchant's Chapa secret API key — via the chapa_proceed WooCommerce API endpoint. The vulnerability was published on February 4, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerable chapa_proceed WooCommerce API endpoint fails to enforce authentication or authorization checks before returning sensitive configuration data, including the merchant's Chapa secret API key. An unauthenticated remote attacker can send a crafted HTTP request to this endpoint and receive the secret key in the response. The vulnerable code path is visible in the plugin source at includes/class-waf-wc-chapa-gateway.php around line 418 (Wordfence, WordPress Trac).
Successful exploitation allows any unauthenticated attacker to retrieve the merchant's Chapa secret API key, which can be used to initiate fraudulent transactions, issue refunds, or otherwise compromise the merchant's payment processing account. This represents a direct financial risk to affected merchants and their customers. While the vulnerability does not directly impact system integrity or availability, the exposure of payment gateway credentials can lead to significant financial fraud and reputational damage (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-15482 as of the available data. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it trivially exploitable by any attacker who identifies a vulnerable WordPress site (Wordfence).
wp-content/plugins/chapa-payment-gateway-for-woocommerce/readme.txt.chapa_proceed WooCommerce API endpoint exposed by the plugin, typically accessible via the WordPress REST API or WooCommerce webhook/callback URL structure.chapa_proceed endpoint without any authentication credentials or session tokens.chapa_proceed WooCommerce API endpoint from unknown or external IP addresses; repeated requests to this endpoint without corresponding legitimate checkout activity.chapa_proceed endpoint from IPs not associated with legitimate customers or payment callbacks; absence of valid WooCommerce session or nonce tokens in these requests.Merchants should update the Chapa Payment Gateway Plugin for WooCommerce to a version beyond 1.0.3 that addresses this vulnerability. If an immediate update is not possible, consider temporarily disabling the plugin and using an alternative payment method. Additionally, merchants should rotate their Chapa secret API key immediately if they suspect exposure, and review Chapa transaction logs for any unauthorized activity (Wordfence).
Wordfence included CVE-2025-15482 in their weekly WordPress vulnerability report for the period of February 2–8, 2026, highlighting it as part of a broader set of plugin vulnerabilities affecting WordPress sites (Wordfence Blog). No significant additional vendor statements or notable researcher commentary beyond the initial disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."