
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49340 is a Sensitive Data Exposure vulnerability (CWE-497) in the Digages Direct Payments WP WordPress plugin that allows authenticated low-privileged users to retrieve embedded sensitive system information. It was reported by researcher Jitlada on October 8, 2025, and publicly disclosed by Patchstack on December 31, 2025. The vulnerability affects Direct Payments WP versions up to and including 1.4.1, with no official patch available as of the latest update. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), meaning the plugin exposes sensitive data in a context accessible to unauthorized parties. Exploitation requires only a low-privileged authenticated account (e.g., Subscriber level) and is conducted over the network with no user interaction required. The attack vector suggests the plugin embeds or surfaces sensitive configuration or system data in responses accessible to authenticated users who should not have access to it, aligning with OWASP Top 10 category A3: Sensitive Data Exposure (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker to view sensitive information not normally accessible to regular users, such as embedded configuration data or system details. While the confidentiality impact is rated as low and there is no integrity or availability impact, the exposed data could be leveraged to facilitate further attacks against the WordPress site or its underlying infrastructure. Patchstack notes this type of vulnerability is sometimes used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-49340. The EPSS score is approximately 0.027%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority with unlikely exploitation impact (Patchstack, Red Hat CVE).
As of the latest available information, no official patch has been released by the plugin developer Digages for the Direct Payments WP plugin. Patchstack recommends updating the affected plugin as the immediate action; if an update is unavailable, site administrators should consult their hosting provider or web developer. As a workaround, administrators may consider deactivating and removing the plugin until a patched version is released, or deploying a web application firewall (WAF) rule via a security plugin such as Patchstack to virtually patch the vulnerability (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."