CVE-2026-103517mediumCWE-345

CVE-2026-103517: falha de média gravidade em Airwallex Online Payments Gateway

Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Webhook

Publicada em

10Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 5.3
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N