cleantalk
Vulnerabilities and Security Researches

Payment forms, Buy now buttons and Invoicing System | GetPaid, CVE-2026-12901

CVE, Research URL

CVE-2026-12901

Published on
Aug 07, 2026
Research Description
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.
Affected versions
max 2.8.55.
Status
vulnerable