CVE-2026-73315 PUBLISHED

XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler

Assigner: VulnCheck
Reserved: 11.08.2026 Published: 08.09.2026 Updated: 09.09.2026

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback endpoint to reach internal network resources including cloud instance metadata services, potentially disclosing IAM credentials or enabling secondary internal service exploitation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor XenForo
Product XenForo
Versions Default: unaffected
  • affected from 0 to 2.3.13 (excl.)

Credits

  • Marco Paciaroni (BomboBombone) finder
  • VulnCheck coordinator

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE