Payment forms, Buy now buttons and Invoicing System | GetPaid, CVE-2026-12901
- CVE, Research URL
- Published on
- Aug 07, 2026
- Research Description
- The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
- Affected versions
-
max 2.8.55.
- Status
-
vulnerable