CVE-2026-3177 MEDIUM

CVE-2026-3177: Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook

Vendor Smub
Product Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
Weakness CWE-345
Published April 7, 2026
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge payment_intent.succeeded webhook payloads and mark pending donations as completed without a real payment.

Explanation of Vulnerability in Simple Terms

02Summary

The Charitable donation plugin for WordPress contains an integrity vulnerability affecting versions up to 1.8.9.7. An attacker on the network can modify data without authentication or user interaction. The vulnerability has low integrity impact and does not affect confidentiality or availability. Site administrators should update to a version newer than 1.8.9.7.

What an attacker can do

03Attacker Capabilities

Modify data on the site over the network without needing to log in.

Potential impact on your site

04Site Impact

Donation data or plugin settings could be altered by an unauthenticated attacker.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

April 7, 2026 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE