Get real-time updates on Telegram
CVE-2026-103517: Airwallex Online Payments Gateway 0 to before 1.36.0
CVE-2026-103517. CVSS 3.1 base score 5.3 (MEDIUM, Vendor/CNA).
Affected technology
Airwallex Online Payments Gateway · 0 to before 1.36.0
Vendor not specified by the source
Description’s affected range: before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source says the Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.
- CWE
- CWE-345
- CCR priority
- 21.2 /100 (P4)
- CVSS 3.1
- 5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N · Vendor/CNA
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 18:27:24.781324+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-103517.html