← WordPress Vulnerabilities
WordPress security by component

getpaid

getpaid adds payment, invoicing, and checkout features for selling products or services through WordPress.

getpaid (getpaid) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 5.9.

Plugin slug: getpaid

CVE-2026-12901: GetPaid accepts forged Worldpay payment notifications before 2.8.55

GetPaid before 2.8.55 lets an unauthenticated attacker submit a forged Worldpay payment notification that the plugin accepts as evidence of payment, causing a pending invoice to be marked paid even though no funds were received. The CNA identifies 2.8.55 as the first unaffected release.

PublishedAug 06, 2026
Known safe version2.8.55
Published vulnerabilities for getpaid
Safe version
Aug 06, 2026 CVE-2026-12901
GetPaid accepts forged Worldpay payment notifications before 2.8.55
GetPaid before 2.8.55 lets an unauthenticated attacker submit a forged Worldpay payment notification that the plugin accepts as evidence of payment, causing a pending invoice to be marked paid even though no funds were received. The CNA identifies 2.8.55 as the first unaffected release.
2.8.55
CVE5.9
NVDPending
Nov 01, 2024 CVE-2024-43973
GetPaid: A security weakness
GetPaid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Jun 21, 2021 CVE-2021-24369
GetPaid: Cross-site scripting
GetPaid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4