CVE-2023-4917: Te-St Leyka
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.
Affected products
- Te-St Leyka: up to and including 3.30.3
Published 2023-09-13. Last modified 2026-06-17.