Credova Financial

Credova Financial has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 3 issues recorded for Credova Financial has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Credova Financial is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Credova Financial vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-32588

Credova_Financial <= 2.4.8 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
Credova Financial banner
Latestv2.6.5

Credova Financial

Credova Financial

Author

Credova Financial

0.0(0)
0/100
Last Updated
2026-06-25 (3mo ago)
Active Installs
100+
Downloads
19,236
Requires WP
5.0.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2019-12-27 (7y ago)

Credova is a consumer financing platform that by integrating into merchant’s checkout process, provides a buy now, pay later payment method. With multiple financing products and offers through one application, customers can access the best consumer financing available on the market.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C