PatchSiren cyber security CVE debrief
CVE-2026-12901 GetPaid CVE debrief
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability affects WordPress sites using the GetPaid plugin for payment processing through Worldpay. The lack of authenticity verification could lead to financial losses due to unauthorized marking of invoices as paid. Administrators should review their site's payment processing configuration and ensure that the plugin is updated to a version that verifies the authenticity of incoming payment notifications. The vulnerability has a CVSS score of 5.9 and a medium severity. Evidence from WPScan indicates a vulnerability in the GetPaid WordPress plugin, but limited details are available about affected versions and potential mitigations. Defenders should verify the authenticity of incoming payment notifications and review compensating controls for exposed systems.
- Vendor
- GetPaid
- Product
- GetPaid WordPress plugin
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-07
Who should care
Administrators of WordPress sites using the GetPaid plugin, particularly those processing payments through Worldpay, should be aware of this vulnerability and take steps to mitigate it. They should review their site's payment processing configuration and ensure that the plugin is updated to a version that verifies the authenticity of incoming payment notifications.
Technical summary
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability has a CVSS score of 5.9 and a medium severity. The plugin is used for payment processing on WordPress sites, and the lack of authenticity verification could lead to financial losses.
Defensive priority
Medium priority due to potential financial impact
Recommended defensive actions
- Verify the authenticity of incoming payment notifications
- Implement additional logging and monitoring for suspicious activity
- Consider upgrading to version 2.8.55 or later of the GetPaid WordPress plugin
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from WPScan indicates a vulnerability in the GetPaid WordPress plugin. Limited details are available about affected versions and potential mitigations. The plugin does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. Defenders should verify the authenticity of incoming payment notifications and review compensating controls for exposed systems.
Official resources
-
CVE-2026-12901 CVE record
CVE.org
-
CVE-2026-12901 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:45.457Z and has not been modified since then.