Security Advisory

CVE-2026-12901

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 17:00:56
Last updated 2026-08-07 14:08:39
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.