Skip to content
Saturday, August 22, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY

CVE-2026-16738

The CVE Severity Digest turns the National Vulnerability Database feed into a prioritized security briefing. It groups affected software into practical product families, distinguishes patch and mitigation references from general citations, and ranks the vulnerabilities most likely to matter to technology operators while preserving direct links to the official record.

Records
199
Last changed
Update schedule
17 6 * * * UTC
Coverage
08/15/2026–08/22/2026
Method
Methodology
CVE
CVE-2026-16738
Description
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Published
08/22/2026
Severity
UNKNOWN
CVSS
Priority score
20