---
id: CVE-2026-96200
title: >-
  The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that
  payment notifications received by its payment callback come from the payment
  provider, allowing unauthenticated attackers to mark arbitrary orders as paid
  without…
summary: >-
  The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that
  payment notifications received by its payment callback come from the payment
  provider, allowing unauthenticated attackers to mark arbitrary orders as paid
  without…
severity: none
cwe:
  - CWE-862
product: Payments for Hubtel
affected:
  - payments_for_hubtel < 1.0.2
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T06:17:16.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96200'
references:
  - url: 'https://wpscan.com/vulnerability/c3ccbe90-6942-46d6-b79b-f3223121eec6/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T06:38:44.655Z'
---

## Overview

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
