VYPR
Unrated severityNVD Advisory· Published Oct 1, 2026

CVE-2026-96200

CVE-2026-96200

Description

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.