MEDIUM
Charitable
CVE published 2026-08-21
CVE-2026-16650
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment. This issue has a CVSS score of 5.3 and is considered medium severity. Users should verify the authenticity of incoming webhook events and u [truncated]