CVE-2026-73316
Severity CVSS v4.0:
HIGH
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
08/09/2026
Last modified:
09/09/2026
Description
XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers can replay a valid webhook payload to trigger duplicate payment events, resulting in repeated subscription activations and unauthorized account upgrades.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://bombobombone.github.io/posts/cve-2026-73316/
- https://github.com/BomboBombone/CVE-2026-73316
- https://www.vulncheck.com/advisories/xenforo-payment-replay-via-paypal-rest-payment-provider
- https://xenforo.com/community/threads/security-fixes-released-for-all-xenforo-and-media-gallery-versions-2-2-0-2-3-12.239856/
- https://xenforo.com/community/threads/xenforo-2-3-13-and-add-ons-released-includes-security-fixes.239857/


