Impact
A WordPress payment plugin fails to confirm that the payment notification it receives originates from the legitimate payment provider. This allows an unauthenticated attacker to craft a callback message that marks any order as paid without a real transaction, enabling fraudulent payments and revenue loss.
Affected Systems
Any website running the Payments for Hubtel WordPress plugin with a version prior to 1.0.2 is vulnerable; the issue does not affect later releases.
Risk and Exploitability
Although the exact exploitation probability is not quantified, the flaw can be leveraged remotely by sending forged callback requests to the plugin’s endpoint. The vulnerability is not listed in CISA KEV, but its potential for financial damage and the lack of input validation make it a high‑risk concern for any site using the affected plugin.
OpenCVE Enrichment