CVE-2026-96200

Published: Ott 01, 2026 Last Modified: Ott 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.

https://wpscan.com/vulnerability/c3ccbe90-6942-46d6-b79b-f3223121eec6/