Medium severity5.3NVD Advisory· Published Aug 21, 2026· Updated Aug 21, 2026
CVE-2026-16650
CVE-2026-16650
Description
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.