CVE-2026-27073
Received
Received - Intake
Hard-coded Credentials in Addi Plugin Enables Password Recovery Exploit
Publication date: 2026-03-25
Last updated on: 2026-04-28
Assigner: Patchstack
Description
Description
Use of Hard-coded Credentials vulnerability in Addi Addi β Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi β Cuotas que se adaptan a ti: from n/a through <= 2.0.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| addi | buy-now-pay-later-addi | to 2.0.4 (inc) |
| patchstack | addi_cuotas_que_se_adaptan_a_ti | to 2.0.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |