Security Advisory
CVE-2026-16650
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.