Impact
The Charitable WordPress plugin prior to version 1.8.12 does not verify the authenticity of incoming Square payment webhook events in its default configuration. This omission allows an attacker to forge webhook notifications that mark donation records as paid without any actual transaction, creating fictitious revenue and compromising financial reporting.
Affected Systems
Any WordPress site running the Charitable plugin version 1.8.11 or earlier with the default webhook signature verification setting disabled is affected. The vulnerability is present because the plugin processes Square webhook requests without performing signature validation.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated external attacker sending HTTP POST requests to the Square webhook endpoint, as the plugin accepts and processes signatures without validation. No credentials are required, and the exploit can be carried out from any location that can reach the site, resulting in false donation status and potential monetary loss.
OpenCVE Enrichment