Exposure of Sensitive Customer Data in Sylius Mollie Payment Plugin
CVE-2026-68501

6.5MEDIUM

Key Information:

Vendor

Sylius

Vendor
CVE Published:
30 July 2026

What is CVE-2026-68501?

The Sylius Mollie Plugin, used for integrating Mollie payment processing, contains a vulnerability that allows unauthenticated access to certain endpoints. Specifically, prior versions (before 2.2.8, 3.2.4, and 3.3.1) allow attackers to sequentially access order data through the GET /{_locale}/thank-you and GET /{_locale}/get-code endpoints without appropriate ownership or session checks. This can lead to the exposure of sensitive customer information, such as first name, last name, and email associated with specific order tokens. Users are advised to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

MolliePlugin < 2.2.8 < 2.2.8

MolliePlugin >= 3.0.0, < 3.2.4 < 3.0.0, 3.2.4

MolliePlugin >= 3.3.0, < 3.3.1 < 3.3.0, 3.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.