Signature Verification Bypass in PayPal REST Webhook Handler of XenForo
CVE-2026-73314
8.7HIGH
What is CVE-2026-73314?
XenForo versions before 2.3.13 are affected by a vulnerability in the PayPal REST webhook handler, where an unauthenticated attacker can exploit a flaw in signature verification logic. This allows malicious users to submit crafted webhook requests with an unsupported auth_algo header value, leading the verification function to erroneously approve these requests. As a result, payment events can be processed without a valid signature from PayPal, potentially leading to unauthorized transactions.
Affected Version(s)
XenForo 0 < 2.3.13
