Description
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Subscription Activation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in XenForo versions earlier than 2.3.13 allows attackers to replay the same PayPal webhook payload because the payment provider does not check for duplicate transaction IDs. This omission lets an attacker trigger multiple payment events for a single transaction, causing repeated subscription activations and unauthorized account upgrades, effectively granting services without payment. The flaw is a CWE‑345 weakness involving insufficient validation of input to prevent duplicate processing.

Affected Systems

The flaw affects the XenForo forum software with the PayPal REST payment provider enabled. Any site running XenForo before version 2.3.13 and using this payment provider module is susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the vulnerability is significant because a single replay can permanently upgrade an account. The flaw is not yet listed in CISA KEV, meaning no documented real‑world exploitation has been recorded. Based on the description, it is inferred that an attacker would need to intercept or craft a valid PayPal webhook payload and send it to the target site; no privileged access is required beyond controlling the source of the webhook.

Generated by OpenCVE AI on September 8, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update XenForo to version 2.3.13 or later by applying the official vendor patch.
  • Temporarily disable or uninstall the PayPal REST payment provider module until the update is applied.
  • Modify the PayPal webhook handling code to check for and reject duplicate transaction IDs, ensuring each transaction is processed only once.

Generated by OpenCVE AI on September 8, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:15:00 +0000


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Xenforo
Xenforo xenforo
Vendors & Products Xenforo
Xenforo xenforo

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
Title XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T15:03:08.112Z

Reserved: 2026-08-11T19:56:20.007Z

Link: CVE-2026-73316

cve-icon Vulnrichment

Updated: 2026-09-10T13:50:28.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T14:17:25.923

Modified: 2026-09-11T20:31:36.417

Link: CVE-2026-73316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:15:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity