Impact
The GetPaid WordPress plugin prior to version 2.8.55 lacks proper verification of incoming Worldpay payment notifications. An attacker can forge the notification and cause a pending invoice to be marked as paid without any real payment transaction, resulting in potential financial loss for the site owner.
Affected Systems
WordPress sites running the GetPaid plugin before version 2.8.55 are affected. The vulnerability exists in all instances of the plugin in this version range and applies to any configuration that uses Worldpay IPN notifications without additional authentication.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. The exploitation likelihood is not quantified (EPSS not available), but the flaw permits unauthenticated attackers to send forged IPN data over the network to the site’s notification endpoint. This remote attack path can lead to unauthorized invoice completion and revenue loss.
OpenCVE Enrichment