{"id":"CVE-2026-96200","title":"The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without…","summary":"The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without…","severity":"none","cwe":["CWE-862"],"product":"Payments for Hubtel","affected":["payments_for_hubtel < 1.0.2"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T06:17:16.120","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96200","references":[{"url":"https://wpscan.com/vulnerability/c3ccbe90-6942-46d6-b79b-f3223121eec6/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T06:38:44.655Z","slug":"CVE-2026-96200","body":"## Overview\n\nThe Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}