CVE-CVE-2026-73316
Severity
HIGH
CVSS Score
7.5
Description
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades....
PoCs for CVE-CVE-2026-73316
CVE-2026-73316
General
Python
0
BomboBombone
2026-09-08