CVE-2026-103517
Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Webhook
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.
| Vendor | unknown |
| Product | airwallex online payments gateway |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown airwallex online payments gateway
Be the first to know when new medium vulnerabilities affecting unknown airwallex online payments gateway are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Airwallex Online Payments Gateway
0 < 1.36.0
References
Credits
Pedro Pinho WPScan