What is CVE-2026-12901?
The GetPaid WordPress plugin before version 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification and mark an invoice as paid without any actual payment. Updating the plugin to version 2.8.55 or higher is recommended.
Azərbaycanca: GetPaid WordPress plaqini 2.8.55 versiyasından əvvəlki versiyalarda Worldpay ödəniş bildirişlərinin həqiqiliyini yoxlamadığı üçün autentifikasiya olunmamış hücumçular saxta bildiriş göndərərək ödəniş olmadan fakturanı ödənilmiş kimi göstərə bilər. Plaqini ən az 2.8.55 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which payment system's notifications are affected by CVE-2026-12901 in the GetPaid plugin?
This vulnerability is related to the lack of verification of incoming Worldpay payment notifications.
What is the minimum version of the GetPaid plugin required to protect against CVE-2026-12901?
It is recommended to update the plugin to at least version 2.8.55.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.