PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103517 Airwallex CVE debrief

The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. This vulnerability affects WordPress sites using the plugin, potentially leading to financial losses. Defenders should prioritize verification and remediation efforts to prevent exploitation. The vulnerability is caused by a lack of verification for incoming payment notifications, which can be forged by unauthenticated attackers.

Vendor
Airwallex
Product
Online Payments Gateway
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for WordPress sites using the Airwallex Online Payments Gateway plugin should assess exposure and prioritize verification and remediation efforts to prevent potential financial losses. This includes verifying the authenticity of payment notifications, upgrading to version 1.36.0 or later, and monitoring payment notifications for suspicious activity. Additionally, defenders should review compensating controls for exposed systems and

Why it matters

CVE-2026-103517 allows unauthenticated attackers to bypass payment verification, potentially leading to financial losses. Defenders should prioritize verification and remediation.

  • Unauthenticated attackers can forge payment notifications
  • Orders can be marked as paid without actual payment
  • Defenders must verify payment notification authenticity
  • Remediation priority is high for sites using affected versions

Technical summary

The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. The vulnerability is caused by a lack of verification for incoming payment notifications, which can be forged by unauthenticated attackers. This can lead to financial losses if exploited. Defenders should prioritize verifying the authenticity of payment notifications and upgrading to version 1.36.0 or later.

Defensive priority

Defenders should prioritize verifying the authenticity of payment notifications and upgrading to version 1.36.0 or later.

Recommended defensive actions

  • Verify the authenticity of payment notifications
  • Upgrade to version 1.36.0 or later
  • Monitor payment notifications for suspicious activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates or mitigations through normal change control

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploitation or affected systems. The vulnerability has been publicly disclosed, and defenders should verify the authenticity of payment notifications and upgrade to version 1.36.0 or later. The source item provides technical details on the vulnerability, but additional information on affected systems and potential exploitation is needed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103517 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103517

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103517 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103517

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.