CVE-2026-73315: XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade XenForo to a version that resolves this vulnerability.

    Fixed in 2.3.13
  2. Compensating control

    Restrict outbound HTTP/S traffic from the XenForo server to prevent SSRF from reaching internal network resources, including cloud instance metadata services.

Event History

Sep 8, 2026
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

XenForo installations running a version earlier than 2.3.13 are affected where the PayPal REST webhook callback endpoint is reachable. The vulnerable handler processes attacker-supplied certificate URLs without scheme, hostname, or allowlist validation.

2

Does exploitation require an account or user interaction?

No. The provided vector indicates network-reachable, low-complexity exploitation with no privileges or user interaction required. An attacker can submit a crafted POST request to the PayPal webhook callback endpoint.

3

What can an attacker access through this flaw?

An attacker can cause the XenForo server to issue outbound HTTP requests to arbitrary destinations, including internal network resources and cloud instance metadata services. This may disclose IAM credentials or provide a path to exploit internal services.

4

What should be done if upgrading cannot happen immediately?

The available data does not specify a vendor-supported workaround. Restricting access to the PayPal webhook callback endpoint and preventing the server from reaching internal resources or cloud metadata services would address the described attack path, but these measures are not stated in the provided advisory data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203