๐Ÿ” CVE Alert

CVE-2026-16738

UNKNOWN 0.0

Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Forgery

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

Vendor unknown
Product conekta payment gateway
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown conekta payment gateway

Be the first to know when new unknown vulnerabilities affecting unknown conekta payment gateway are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Conekta Payment Gateway
0 < 6.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/89a2917e-032c-4f0f-be44-1a50b9d6fddf/

Credits

Pedro Pinho WPScan