Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12901

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

EPSS

Процентиль: 3%
0.00125
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 5.9
github
12 дней назад

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

EPSS

Процентиль: 3%
0.00125
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-345