CVE-2026-3177Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhook events. This makes it possible for unauthenticated attackers to forge payment_intent.succeeded webhook payloads and mark pending donations as completed without a real payment.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-19)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-07: 1Mentions · 2026-04-19: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-19: 204-0704-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-192
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3177 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Aut… https://www.cve.org/CVERecord?id=CVE-2026-3177 ----- Traducción: CVE-2026-3177 The… http://infoflow.cloud`

    Post summary

    The tweet announces that CVE‑2026‑3177 affects the Charitable WordPress donation plugin due to insufficient data authentication verification, and provides a link to the official CVE record.

    0000038
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3177 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Aut… https://www.cve.org/CVERecord?id=CVE-2026-3177

    Post summary

    The notice simply announces a CVE for a WordPress plugin and briefly describes the vulnerability type without providing PoC, exploit, patch or exploitation evidence.

    00000202
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3177 Insufficient Webhook Verification in Charitable WordPress Donation Plugin Up to 1.8.9.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3177

    Post summary

    The text announces CVE‑2026‑3177, a webhook verification flaw affecting Charitable WordPress Donation Plugin up to version 1.8.9.7, and provides a link to vulnerability details.

    0000046
    4.0K followersView on X

Explore more