CVE-2024-38747: Hitpay Payment Gateway For Woocommerce
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway for WooCommerce: from n/a through 4.1.3.
Affected products
- Hitpay Payment Gateway For Woocommerce: up to and including 4.1.3
- Hitpay Payment Solutions Pte Ltd Hitpay Payment Gateway For Woocommerce: up to and including 4.1.3
Published 2024-08-13. Last modified 2026-06-17.