CVE-2026-12901
MEDIUM
NVD
CVSS Score
5.9
Severity
MEDIUM
Published
Aug 06, 2026
Vendor
unknown
Description
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.