CVE-2026-96200

NONE
Updated Oct 01, 2026
WordPress
Parameter Value
Affected Versions before 1.0.2
Type CWE-862 Missing Authorization
Vendor WordPress
Public PoC No

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

Vulnerable Products

unknown:payments for hubtel