CVE-2026-49066: WordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unauthenticated sensitive data exposure vulnerability affects the Conekta Payment Gateway WordPress plugin at version 6.0.0 and earlier. The flaw is reachable over the network without any credentials, meaning any internet-connected attacker can trigger it directly. Successful exploitation grants read access to sensitive data handled by the plugin, such as payment-related configuration or transaction details. No fix version has been published yet; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as an upstream fix is released.
HarborGuard Coverage
Detection for CVE-2026-49066 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built WordPress images that bundle the Conekta Payment Gateway plugin. Any image at plugin version 6.0.0 or earlier is flagged automatically.
AvailableHarborGuard is capable of scoring this CVE at CVSS 7.5 HIGH and weighting the result against each customer environment's compliance policy to determine urgency. Triage findings can be routed to the appropriate team inbox within each customer organization based on configured policy rules.
AvailableBecause no fix version has been published upstream, HarborGuard re-checks the Conekta Payment Gateway advisory on every ingest cycle and will make a patched-image rebuild available the moment a fix is released. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will be triggered automatically at that point.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The plugin endpoint is exposed over the network, so an attacker must be able to reach the WordPress installation via HTTP or HTTPS from any internet-connected location.
- AuthenticationNot required
No account or session credential of any kind is needed to trigger the vulnerability.
- Victim interactionNot required
The attacker can exploit this directly without any action from a logged-in user or site visitor.
- Attack complexityDetail
The exploit is reliable and condition-free, requiring no race conditions, special memory layout, or environmental prerequisites.
Blast Radius
- A successful attacker reads sensitive data exposed by the payment gateway plugin, which may include API keys, private keys, or payment configuration values used to authenticate with Conekta services.
- Access to Conekta API credentials could allow an attacker to query transaction records or customer payment data held in the Conekta platform outside the WordPress host.
- There is no integrity or availability impact from this vulnerability; the attacker gains read access only and does not modify or disrupt the WordPress installation itself.
How HarborGuard Handles This
Available on HarborGuard: detection for this CVE is active across customer environments now, flagging any scanned image that bundles Conekta Payment Gateway at version 6.0.0 or earlier. Because no upstream fix exists at this time, HarborGuard monitors the advisory on each ingest cycle and will trigger a patched-image rebuild automatically the moment a fix version is published. For customers with auto-remediation enabled, that rebuild will be followed by a regression test run and a PR opened against affected workloads. In the interim, compensating controls worth considering include network-policy rules that restrict inbound access to the WordPress installation to known-good sources, egress filtering to limit outbound connections from the container to only required payment endpoints, and disabling the Conekta plugin if payment processing is not actively needed in the affected environment. Where compliance policy requires a manual approval step, triage findings are routed to the designated inbox so the right team can act without delay.
- Conekta Group / Conekta Payment Gateway≤ 6.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N