MEDIUM
GetPaid
CVE published 2026-08-06
CVE-2026-12901
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. This vulnerability affects WordPress sites using the GetPaid plugin for payment processing through Worldpay. The lack of authenticity verification could lead to [truncated]