Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w426-cmgx-r837

Опубликовано: 07 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

EPSS

Процентиль: 3%
0.00125
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 5.9
nvd
12 дней назад

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

EPSS

Процентиль: 3%
0.00125
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345