WordPress Gerencianet Oficial <= 3.1.3 - Unauthenticated Order Status Disclosure
CVE-2025-59136
Verified
Description
Efí Bank Gerencianet Oficial <= 3.1.3 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve embedded sensitive data, exploit requires crafted requests.
Severity
Medium
Published Date
April 23, 2026
Template Author
pussycat0x
CVE-2025-59136.yaml
5.0Severity
CVSS Metrics
References
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-gerencianet-official/gerencianet-oficial-313-unauthenticated-information-exposurehttps://patchstack.com/database/wordpress/plugin/woo-gerencianet-official/vulnerability/wordpress-gerencianet-oficial-plugin-3-1-3-sensitive-data-exposure-vulnerability
Remediation Steps
Update to the latest version beyond 3.1.3.