PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12901 GetPaid CVE debrief

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability affects WordPress sites using the GetPaid plugin for payment processing through Worldpay. The lack of authenticity verification could lead to financial losses due to unauthorized marking of invoices as paid. Administrators should review their site's payment processing configuration and ensure that the plugin is updated to a version that verifies the authenticity of incoming payment notifications. The vulnerability has a CVSS score of 5.9 and a medium severity. Evidence from WPScan indicates a vulnerability in the GetPaid WordPress plugin, but limited details are available about affected versions and potential mitigations. Defenders should verify the authenticity of incoming payment notifications and review compensating controls for exposed systems.

Vendor
GetPaid
Product
GetPaid WordPress plugin
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Administrators of WordPress sites using the GetPaid plugin, particularly those processing payments through Worldpay, should be aware of this vulnerability and take steps to mitigate it. They should review their site's payment processing configuration and ensure that the plugin is updated to a version that verifies the authenticity of incoming payment notifications.

Technical summary

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability has a CVSS score of 5.9 and a medium severity. The plugin is used for payment processing on WordPress sites, and the lack of authenticity verification could lead to financial losses.

Defensive priority

Medium priority due to potential financial impact

Recommended defensive actions

  • Verify the authenticity of incoming payment notifications
  • Implement additional logging and monitoring for suspicious activity
  • Consider upgrading to version 2.8.55 or later of the GetPaid WordPress plugin
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from WPScan indicates a vulnerability in the GetPaid WordPress plugin. Limited details are available about affected versions and potential mitigations. The plugin does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. Defenders should verify the authenticity of incoming payment notifications and review compensating controls for exposed systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:45.457Z and has not been modified since then.