CWE-345— Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.— MITRE CWE catalog
841 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-345page 14 of 17
- CVE-2026-92996MEDIUMCVSS 5.3EG 5.32026-09-28
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
- CVE-2026-89411MEDIUMCVSS 5.3EG 5.32026-09-28
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a small…
- CVE-2026-87978MEDIUMCVSS 5.3EG 5.32026-09-23
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
- CVE-2026-92400MEDIUMCVSS 5.3EG 5.32026-09-21
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account befor…
- CVE-2026-78296MEDIUMCVSS 5.3EG 5.32026-09-17
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
- CVE-2026-84906MEDIUMCVSS 5.3EG 5.32026-09-16
The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or whi…
- CVE-2026-86809MEDIUMCVSS 5.3EG 5.32026-09-11
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete…
- CVE-2026-83537MEDIUMCVSS 5.3EG 5.32026-09-09
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
- CVE-2026-85008MEDIUMCVSS 5.3EG 5.32026-09-04
undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is nev…
- CVE-2026-84043MEDIUMCVSS 5.3EG 5.32026-09-04
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signatur…
- CVE-2026-84767MEDIUMCVSS 5.3EG 5.32026-09-03
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
- CVE-2026-83533MEDIUMCVSS 5.3EG 5.32026-09-02
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
- CVE-2026-82465MEDIUMCVSS 5.3EG 5.32026-08-29
pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowin…
- CVE-2026-16650MEDIUMCVSS 5.3EG 5.32026-08-21
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as p…
- CVE-2026-15150MEDIUMCVSS 5.3EG 5.32026-08-21
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site…
- CVE-2026-73840MEDIUMCVSS 5.3EG 5.32026-08-13
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provide…
- CVE-2026-15239MEDIUMCVSS 5.3EG 5.32026-08-07
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable…
- CVE-2026-15148MEDIUMCVSS 5.3EG 5.32026-08-07
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated …
- CVE-2026-15208MEDIUMCVSS 5.3EG 5.32026-08-06
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is…
- CVE-2026-15147MEDIUMCVSS 5.3EG 5.32026-08-06
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the inten…
- CVE-2026-14936MEDIUMCVSS 5.3EG 5.32026-08-06
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or ext…
- CVE-2026-12501MEDIUMCVSS 5.3EG 5.32026-08-06
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking …
- CVE-2026-15152MEDIUMCVSS 5.3EG 5.32026-08-06
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated u…
- CVE-2026-59641MEDIUMCVSS 5.3EG 5.32026-08-03
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips …
- CVE-2026-28145MEDIUMCVSS 5.3EG 5.32026-07-31
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
- CVE-2026-62517MEDIUMCVSS 5.3EG 5.32026-07-21
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated atta…
- CVE-2026-44434MEDIUMCVSS 5.3EG 5.32026-07-16
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. The QUIC protocol is…
- CVE-2026-53536MEDIUMCVSS 5.3EG 5.32026-07-16
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined w…
- CVE-2026-11901MEDIUMCVSS 5.3EG 5.32026-07-11
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal…
- CVE-2026-52737MEDIUMCVSS 5.3EG 5.32026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block who…
- CVE-2026-9242MEDIUMCVSS 5.3EG 5.32026-06-27
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and includ…
- CVE-2026-48096MEDIUMCVSS 5.3EG 5.32026-06-10
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result …
- CVE-2026-7792MEDIUMCVSS 5.3EG 5.32026-06-06
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to…
- CVE-2026-8608MEDIUMCVSS 5.3EG 5.32026-06-05
The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handle…
- CVE-2026-9189MEDIUMCVSS 5.3EG 5.32026-05-29
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correc…
- CVE-2026-44999MEDIUMCVSS 5.3EG 5.32026-05-11
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue…
- CVE-2026-6498MEDIUMCVSS 5.3EG 5.32026-04-30
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) betwe…
- CVE-2026-3177MEDIUMCVSS 5.3EG 5.32026-04-07
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to…
- CVE-2026-33221MEDIUMCVSS 5.3EG 5.32026-03-20
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an…
- CVE-2026-32029MEDIUMCVSS 5.3EG 5.32026-03-19
OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or prese…
- CVE-2025-52645MEDIUMCVSS 5.3EG 5.32026-03-16
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentiall…
- CVE-2026-2385MEDIUMCVSS 5.3EG 5.32026-02-22
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. T…
- CVE-2025-14444MEDIUMCVSS 5.3EG 5.32026-02-18
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' …
- CVE-2026-0939MEDIUMCVSS 5.3EG 5.32026-01-16
The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and including, 5.1.2. This is due to the plugin failing to verify t…
- CVE-2025-15154MEDIUMCVSS 5.3EG 5.32025-12-28
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For le…
- CVE-2025-12752MEDIUMCVSS 5.3EG 5.32025-11-22
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This m…
- CVE-2025-12245MEDIUMCVSS 5.3EG 5.32025-10-27
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl l…
- CVE-2024-55929MEDIUMCVSS 5.3EG 5.32025-01-23
A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as though messages are sent from trusted sources.
- CVE-2024-47123MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is recommended to continu…
- CVE-2024-43108MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message. It is advised to con…
Map vulnerabilities like CWE-345 to your infrastructure
EchelonGraph correlates every CVE — across CWE-345 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →