Description
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 08 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades. | |
| Title | XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider | |
| Weaknesses | CWE-345 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:18:35.469Z
Reserved: 2026-08-11T19:56:20.007Z
Link: CVE-2026-73316
No data.
Status : Received
Published: 2026-09-08T14:17:25.923
Modified: 2026-09-08T14:17:25.923
Link: CVE-2026-73316
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-345
Insufficient Verification of Data Authenticity