CVE-2026-3177: Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge paymentintent.succeeded webhook payloads and mark pending donations as completed without a real payment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3177?
CVE-2026-3177 is considered a high-severity vulnerability due to its potential for unauthorized manipulation of donation statuses.
How do I fix CVE-2026-3177?
To fix CVE-2026-3177, update the Charitable Donation Plugin for WordPress to a version later than 1.8.9.7.
What is the impact of CVE-2026-3177?
The impact of CVE-2026-3177 includes possible donation status forgery, leading to financial loss and undermining trust in the fundraising process.
Who is affected by CVE-2026-3177?
Users of the Charitable Donation Plugin for WordPress version 1.8.9.7 and earlier are affected by CVE-2026-3177.
What type of vulnerability is CVE-2026-3177?
CVE-2026-3177 is categorized as an insufficient verification of data authenticity vulnerability.