CVE-2026-12901 MEDIUM

CVE-2026-12901: GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification

Vendor Unknown
Product GetPaid
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

Explanation of Vulnerability in Simple Terms

02Summary

GetPaid versions before 2.8.55 contain an integrity vulnerability that allows an attacker to modify data or functionality without authentication. The attack requires specific network conditions and cannot be exploited remotely without additional setup. No confidentiality or availability impact occurs. Update to version 2.8.55 or later to resolve this issue.

What an attacker can do

03Attacker Capabilities

Modify or tamper with site data or functionality without needing to log in.

Potential impact on your site

04Site Impact

Unauthorized changes to site data or behavior; integrity of transactions or settings cannot be guaranteed.

Conditions required to exploit

05Prerequisites

Attacker must have network access and meet specific technical conditions; no user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published