CVE-2026-73316
Analyzed Analyzed - Analysis Complete

XenForo Payment Replay in PayPal REST Provider

Vulnerability report for CVE-2026-73316, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-11

Assigner: VulnCheck

Description

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xenforo xenforo to 2.3.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73316 is a payment replay vulnerability in XenForo versions before 2.3.13. It involves the PayPal REST payment provider processing the same valid webhook payload multiple times due to a missing duplicate transaction ID check. Attackers can replay a legitimate webhook to trigger duplicate payment events, causing repeated subscription activations and unauthorized account upgrades.

Detection Guidance

To detect this vulnerability, check XenForo payment logs for duplicate transaction IDs in PayPal REST webhook callbacks. Look for multiple entries with the same transaction ID triggering subscription activations or account upgrades. Review webhook delivery logs for repeated HTTP 200 responses to the same callback. Compare your XenForo version against 2.3.13; versions prior to this are vulnerable.

Impact Analysis

This vulnerability can lead to financial losses from duplicate payments, unauthorized account upgrades, and extended subscriptions without additional payment. Users may experience unexpected service access or billing issues. Attackers can exploit it by capturing and replaying a valid webhook payload.

Mitigation Strategies

Immediately upgrade XenForo to version 2.3.13 or later to apply the fix for duplicate transaction ID handling. If upgrading is not possible, disable the PayPal REST payment provider until patched. Monitor payment logs for suspicious duplicate transactions and revoke any unauthorized account upgrades caused by replayed webhooks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73316. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart