Impact
The vulnerability in XenForo versions earlier than 2.3.13 allows attackers to replay the same PayPal webhook payload because the payment provider does not check for duplicate transaction IDs. This omission lets an attacker trigger multiple payment events for a single transaction, causing repeated subscription activations and unauthorized account upgrades, effectively granting services without payment. The flaw is a CWE‑345 weakness involving insufficient validation of input to prevent duplicate processing.
Affected Systems
The flaw affects the XenForo forum software with the PayPal REST payment provider enabled. Any site running XenForo before version 2.3.13 and using this payment provider module is susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the vulnerability is significant because a single replay can permanently upgrade an account. The flaw is not yet listed in CISA KEV, meaning no documented real‑world exploitation has been recorded. Based on the description, it is inferred that an attacker would need to intercept or craft a valid PayPal webhook payload and send it to the target site; no privileged access is required beyond controlling the source of the webhook.
OpenCVE Enrichment