CVE-2026-16650
Received Received - Intake

Charitable Plugin Square Webhook Authentication Bypass

Vulnerability report for CVE-2026-16650, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: WPScan

Description

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
charitable charitable to 1.8.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Charitable WordPress plugin before version 1.8.12 has a flaw where it does not verify the authenticity of Square payment webhook events. This allows unauthenticated attackers to send fake webhook notifications that make donations appear as paid without any actual payment being made.

Detection Guidance

Check if the Charitable WordPress plugin version is below 1.8.12. Inspect webhook logs for Square payment notifications marked as paid without corresponding transactions. Look for unusual donation status changes in the plugin's admin panel.

Impact Analysis

This vulnerability could lead to financial losses for organizations using the plugin, as fake donations may be recorded as paid. It could also damage trust with donors and affect the integrity of donation records.

Mitigation Strategies

Update the Charitable plugin to version 1.8.12 or later immediately. Verify Square webhook signatures in the plugin settings to ensure authenticity of payment notifications. Monitor donation records for unauthorized status changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16650. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart