Skip to content
CVE Alert: CVE-2026-73314 – XenForo

CVE Alert: CVE-2026-73314 – XenForo

Redpacketsecurity admin September 8, 2026

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing the caller to treat the fabricated request as verified and process the payment event without a valid PayPal signature.

High risk to payment integrity; remediate urgently, although KEV status, SSVC exploitation state, EPSS probability and active exploitation evidence are not provided.

An attacker may be able to forge payment notifications, causing the forum to record transactions that PayPal did not authorise. Likely outcomes include fraudulent credits, goods or service entitlement, accounting discrepancies, customer disputes and loss of trust; confidentiality and service availability appear less directly affected.

### Most likely attack path

The route is remotely reachable (AV:N), requires low effort (AC:L), no privileges (PR:N) and no user action (UI:N), with unchanged scope. An attacker would submit a crafted webhook request that abuses malformed or unsupported authentication metadata; successful processing could alter payment-related records, but the supplied scope metrics do not indicate direct compromise of other security authorities or automatic lateral movement.

### Who is most exposed

Internet-facing communities using the affected payment integration for subscriptions, donations, shop transactions or automated membership upgrades are most exposed. Risk increases where webhook processing is enabled by default, payment events grant privileges, or reconciliation is infrequent.

Alert on webhook requests with unsupported, unusual or missing algorithm headers.

Correlate accepted webhook events with absent or mismatched PayPal transaction IDs.

Review sudden credits, refunds, membership upgrades or duplicate payment notifications.

Compare application, reverse-proxy and PayPal logs for anomalous source patterns.

### Mitigation and prioritisation

Apply the vendor’s security update at the earliest normal emergency-change window; test payment flows first.

Until patched, reject unsupported algorithms at the edge and restrict the endpoint to verified provider networks where operationally safe.

Require transaction reconciliation before granting high-value entitlements.

Review and reverse suspicious payment-driven changes, preserving logs for investigation.

EPSS and exploitation-status data are needed to refine ordering against other urgent exposures.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (1)