๐Ÿ” CVE Alert

CVE-2026-96200

UNKNOWN 0.0

Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

Vendor unknown
Product payments for hubtel
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown payments for hubtel

Be the first to know when new unknown vulnerabilities affecting unknown payments for hubtel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Payments for Hubtel
0 < 1.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c3ccbe90-6942-46d6-b79b-f3223121eec6/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan