CVE-2026-3177
MEDIUMCharitable for WordPress <= 1.8.9.7 - Donation Status Forgery via Missing Stripe Webhook Verification
Title source: manualDescription
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge payment_intent.succeeded webhook payloads and mark pending donations as completed without a real payment.
Scores
CVSS v3
5.3
EPSS
0.0001
EPSS Percentile
0.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-345
Status
published
Products (1)
smub/Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
< 1.8.9.7
Published
Apr 07, 2026
Tracked Since
Apr 07, 2026