CVE-2026-16650: Unknown Charitable

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.

Affected products

  • Unknown Charitable: before 1.8.12 (fixed in 1.8.12)

Published 2026-08-21. Last modified 2026-08-26.