Description


The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.

Related CPE's


Could not find any relations

Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-345

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T11:16:42.613Z

21 hours ago

Last modified

2026-10-08T20:51:18.123Z

12 hours ago