CVE-2026-96200
Received Received - Intake

Unauthenticated Payment Status Manipulation in Hubtel WordPress Plugin

Vulnerability report for CVE-2026-96200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: WPScan

Description

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hubtel payments_for_hubtel to 1.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Payments for Hubtel WordPress plugin before version 1.0.2. It allows unauthenticated attackers to forge payment confirmations by exploiting a delayed payment callback mechanism. The plugin fails to verify that payment notifications come from the legitimate payment provider, enabling attackers to mark arbitrary orders as paid without actual payment.

Detection Guidance

Check if your WordPress site uses the 'Payments for Hubtel' plugin version prior to 1.0.2. Logs may show unauthorized order status changes without payment. Review callback requests to the plugin for forged payment confirmations.

Impact Analysis

Attackers could exploit this to trick the system into marking orders as paid without real transactions, leading to financial losses. Merchants using the vulnerable plugin might fulfill orders without receiving payment, while customers could be charged for unpaid items.

Compliance Impact

This vulnerability could lead to unauthorized transactions being marked as paid, potentially violating data integrity and financial compliance requirements under standards like GDPR (data protection) and HIPAA (healthcare transactions). Unverified payment confirmations may result in improper financial record-keeping, which could be considered a compliance failure.

Mitigation Strategies

Update the 'Payments for Hubtel' plugin to version 1.0.2 or later immediately. Monitor order statuses for unauthorized changes and review payment callback logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96200. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart