Description
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Signature verification bypass enabling forged PayPal webhook processing
Action: Patch Immediately
AI Analysis

Impact

The flaw in XenForo's PayPal REST webhook handling allows an attacker to send a webhook with an unsupported auth_algo header, causing the signature verification logic to incorrectly return true when it cannot find a matching hash function. The caller interprets this as a valid signature and processes the payment event, enabling the attacker to fabricate payment notifications. This bypass leads to unauthorized payment processing or potential manipulation of payment data.

Affected Systems

This vulnerability affects XenForo forum software versions earlier than 2.3.13. The CNA indicates XenForo:XenForo as the affected product and no precise patch versions beyond 2.3.13. Thus any deployment of XenForo prior to 2.3.13 is susceptible.

Risk and Exploitability

The issue carries a CVSS score of 8.7, indicating high severity, and is not listed in CISA's KEV catalog. The EPSS score is unavailable, so the current exploitation probability is unknown, but the flaw permits unauthenticated attackers to create forged webhook requests, making it potentially exploitable over the network. The lack of authentication required for the exploit and the simplicity of the crafted request suggest a realistic risk for any exposed PayPal webhook endpoint. Attackers would typically target publicly reachable webhook URLs to inject malicious payment events.

Generated by OpenCVE AI on September 8, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade XenForo to version 2.3.13 or later to enforce correct signature verification
  • Disable or restrict access to the PayPal REST webhook endpoint until the update is applied
  • Validate the auth_algo header against a whitelist of supported hash functions and reject unsupported values explicitly
  • Enable logging and alerts for payment events that do not match expected signatures to detect potential abuse

Generated by OpenCVE AI on September 8, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.
Title XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T13:46:20.258Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73314

cve-icon Vulnrichment

Updated: 2026-09-10T13:46:12.695Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:25.640

Modified: 2026-09-11T20:31:16.703

Link: CVE-2026-73314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:15:17Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions