CVE-2026-16650: Unknown Charitable
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
Affected products
- Unknown Charitable: before 1.8.12 (fixed in 1.8.12)
Published 2026-08-21. Last modified 2026-08-26.