CVE-2026-16650: Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/charitableto a version that resolves this vulnerability.Fixed in 1.8.12
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using the Charitable WordPress plugin before version 1.8.12 are exposed when operating with the affected default configuration. The issue concerns Square payment webhook handling.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can forge Square webhook notifications because incoming webhook events are not authenticated in the affected default configuration.
What is the practical impact of successful exploitation?
Forged webhook notifications can cause donations to be marked as paid even though no real payment was made. The provided impact information indicates integrity impact without confidentiality or availability impact.