CVE-2026-3177
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge payment_intent.succeeded webhook payloads and mark pending donations as completed without a real payment.
| CWE | CWE-345 |
| Vendor | smub |
| Product | charitable – donation plugin for wordpress – fundraising with recurring donations & more |
| Published | Apr 7, 2026 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for smub charitable – donation plugin for wordpress – fundraising with recurring donations & more
Be the first to know when new medium vulnerabilities affecting smub charitable – donation plugin for wordpress – fundraising with recurring donations & more are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
smub / Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
0 ≤ 1.8.9.7
References
Credits
Andrés Cruciani