Stripe Secret Key is exposed in the front-end
-
The following file plugs the secret key into the front end:
wp-content/plugins/fundpress/inc/gateways/stripe/class-dn-payment-stripe.php (Line 270).Upon inspection of the source for a page, the following is exposed the front end:
var Donate_Stripe_Settings = {“Secret_Key”:”sk_live_[key redacted]”}This information should NOT be publicly exposed.
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Stripe Secret Key is exposed in the front-end’ is closed to new replies.