Payment Replay Vulnerability in XenForo by XenForo Limited
CVE-2026-73316

8.7HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-73316?

XenForo versions prior to 2.3.13 are susceptible to a payment replay vulnerability in the PayPal REST payment provider. This flaw enables attackers to exploit the absence of a duplicate transaction ID check, allowing them to replay valid webhook payloads. As a result, this can lead to repeated payment events such as unauthorized subscription activations and upgrades to user accounts. Organizations utilizing XenForo should promptly update their systems to mitigate this security risk.

Affected Version(s)

XenForo 0 < 2.3.13

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Paciaroni (BomboBombone)
VulnCheck
.