Answer in brief
CVE-2026-96173 records a Unknown severity vulnerability in Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR. The current sources do not mark it as known exploited. The current feed maps Unknown/Payments for Hubtel (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Payments for Hubtel (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Payments for Hubtelgeneric | >=0 <1.0.2 | 1.0.2 |
Published upstream
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 1, 2026
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents.
Quoted source text, attributed separately from HOL analysis.