High-Risk Vulnerabilities in XenForo Payment Processing

High-Risk Vulnerabilities in XenForo Payment Processing

First seen 8 Sep 2026, 15:46 UTC Redpacketsecurityxenforo.com 64.5

Article Content

Browse articles
ThreatCluster

XenForo versions prior to 2.3.13 are affected by two critical vulnerabilities: CVE-2026-73314 and CVE-2026-73315. CVE-2026-73314 allows unauthenticated attackers to bypass PayPal payment signature validation, risking fraudulent transactions. CVE-2026-73315 enables server-side request forgery, allowing attackers to make outbound HTTP requests to arbitrary destinations, potentially exposing sensitive internal resources. Both vulnerabilities pose high risks to internet-facing deployments, particularly those using PayPal for transactions. Immediate remediation is advised, although active exploitation has not been reported for CVE-2026-73315. Administrators are urged to apply security updates and implement additional monitoring and filtering measures to mitigate these risks.

Key Points: • CVE-2026-73314 allows bypassing PayPal signature validation, risking fraudulent payments. • CVE-2026-73315 enables server-side request forgery, exposing internal resources. • Both vulnerabilities affect XenForo versions prior to 2.3.13 and require urgent remediation.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-73314 published
XenForo disclosed a signature verification logic error in the PayPal webhook handler, allowing payment fraud.
Redpacketsecurity
2026-09-08
CVE-2026-73315 published
XenForo disclosed a server-side request forgery vulnerability in the PayPal webhook handler, risking internal resource exposure.
Redpacketsecurity