Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-96200
CVE-2026-96200
Description
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Affected products
1- Range: <1.0.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.