
CVE-2026-16738 The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed p… https://www.cve.org/CVERecord?id=CVE-2026-16738
Post summary
The post discloses that the Conekta Payment Gateway WordPress plugin versions prior to 6.2.2 are vulnerable due to lack of verification for incoming webhook notifications, pointing to CVE-2026-16738.

