Payment Replay Vulnerability in XenForo by XenForo Limited
CVE-2026-73316
8.7HIGH
What is CVE-2026-73316?
XenForo versions prior to 2.3.13 are susceptible to a payment replay vulnerability in the PayPal REST payment provider. This flaw enables attackers to exploit the absence of a duplicate transaction ID check, allowing them to replay valid webhook payloads. As a result, this can lead to repeated payment events such as unauthorized subscription activations and upgrades to user accounts. Organizations utilizing XenForo should promptly update their systems to mitigate this security risk.
Affected Version(s)
XenForo 0 < 2.3.13
