CVE-2026-73316: XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider

Published Sep 8, 2026
·
Updated

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.

Affected Software

1 affected component
XenForo Xenforo<2.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade XenForo to a version that resolves this vulnerability.

    Fixed in 2.3.13
  2. Compensating control

    Apply a duplicate-transaction guard for PayPal REST webhook handling by enforcing a missing duplicate transaction ID check (reject webhook processing when the transaction ID was already processed) until XenForo is upgraded to 2.3.13.

Event History

Sep 8, 2026
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

XenForo versions before 2.3.13 are affected when they use the PayPal REST payment provider. The issue concerns processing of PayPal REST webhook payloads.

2

What does an attacker need to exploit it?

An attacker needs a valid webhook payload that can be replayed. No authentication, user interaction, or complex exploitation conditions are indicated by the supplied severity vector.

3

What is the practical impact of a successful replay?

Replaying the same payload can trigger duplicate payment events. This can cause repeated subscription activations and unauthorized account upgrades.

4

How can administrators determine whether they may be affected?

Check whether the XenForo installation is earlier than 2.3.13 and whether the PayPal REST payment provider is enabled or used for payment processing. Review payment and subscription records for repeated processing associated with the same transaction or webhook payload.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203