Back to database
Schedule53Medium5.3VulnerabilityCVE-2026-103517No patch link observed

CVE-2026-103517 — The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the…

Published Oct 8, 2026, 11:16 AM UTCIngested 13h agoSource NVD(cve-db)CVE-2026-103517

Description

The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

Low

Integrity

A

None

Availability