Medium severity5.3NVD Advisory· Published Oct 8, 2026
CVE-2026-103517
CVE-2026-103517
Description
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.36.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.