CVE-2023-4917

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:te-st:leyka:*:*:*:*:*:wordpress:*:*

History

08 Apr 2026, 19:18

Type Values Removed Values Added
Summary (en) The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.3 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords. (en) The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.
CWE CWE-200
References
  • () https://plugins.trac.wordpress.org/changeset/2990146/leyka -

21 Nov 2024, 08:36

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/leyka/tags/3.30.3/inc/leyka-ajax.php#L393 - Third Party Advisory () https://plugins.trac.wordpress.org/browser/leyka/tags/3.30.3/inc/leyka-ajax.php#L393 - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/dcd24b90-94ff-4625-8e3e-9c90e38683f9?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/dcd24b90-94ff-4625-8e3e-9c90e38683f9?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

07 Nov 2023, 04:23

Type Values Removed Values Added
CWE CWE-200

15 Sep 2023, 15:27

Type Values Removed Values Added
References (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/dcd24b90-94ff-4625-8e3e-9c90e38683f9?source=cve - (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/dcd24b90-94ff-4625-8e3e-9c90e38683f9?source=cve - Third Party Advisory
References (MISC) https://plugins.trac.wordpress.org/browser/leyka/tags/3.30.3/inc/leyka-ajax.php#L393 - (MISC) https://plugins.trac.wordpress.org/browser/leyka/tags/3.30.3/inc/leyka-ajax.php#L393 - Third Party Advisory
CPE cpe:2.3:a:te-st:leyka:*:*:*:*:*:wordpress:*:*
First Time Te-st leyka
Te-st
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

13 Sep 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 03:15

Updated : 2026-04-08 19:18


NVD link : CVE-2023-4917

Mitre link : CVE-2023-4917

CVE.ORG link : CVE-2023-4917


JSON object : View

Products Affected

te-st

  • leyka
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor