PatchSiren

Charitable CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Charitable CVE published 2026-08-21

CVE-2026-16650

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment. This issue has a CVSS score of 5.3 and is considered medium severity. Users should verify the authenticity of incoming webhook events and u [truncated]