VYPR

Super Payments

by WordPress

CVEs (1)

  • CVE-2026-103329MedOct 9, 2026
    risk 0.34cvss 5.3epss —

    The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark…