CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-103517: Airwallex Online Payments Gateway 0 to before 1.36.0

CVE-2026-103517. CVSS 3.1 base score 5.3 (MEDIUM, Vendor/CNA).

Affected technology

Airwallex Online Payments Gateway · 0 to before 1.36.0
Vendor not specified by the source

Description’s affected range: before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says the Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.

Published

CWE
CWE-345
CCR priority
21.2 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-103517.html