The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
CVE-2026-96200
NONE
Updated Oct 01, 2026
WordPress
unknown:payments for hubtel
CVE Details
CVE ID
CVE-2026-96200
Published Date
Oct 01, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory