CVE-2023-4917: Te-St Leyka

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.

Affected products

  • Te-St Leyka: up to and including 3.30.3

Published 2023-09-13. Last modified 2026-06-17.