Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpcharitable Wpcharitable charitable |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpcharitable Wpcharitable charitable |
Fri, 21 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-285 |
Fri, 21 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-285 |
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 |
Fri, 21 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment. | |
| Title | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T12:47:51.251Z
Reserved: 2026-07-22T17:23:37.828Z
Link: CVE-2026-16650
Updated: 2026-08-21T12:47:48.238Z
Status : Received
Published: 2026-08-21T12:16:23.870
Modified: 2026-08-21T13:16:54.317
Link: CVE-2026-16650
No data.
OpenCVE Enrichment
Updated: 2026-08-21T20:30:07Z
-
CWE-345
Insufficient Verification of Data Authenticity