PatchSiren

GetPaid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM GetPaid CVE published 2026-08-06

CVE-2026-12901

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability affects WordPress sites using the GetPaid plugin for payment processing through Worldpay. The lack of authenticity verification could lead to [truncated]