CVE-2026-16650
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Aug 21, 2026
Vendor
unknown
Description
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.