PatchSiren cyber security CVE debrief
CVE-2026-103517 Airwallex CVE debrief
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. This vulnerability affects WordPress sites using the plugin, potentially leading to financial losses. Defenders should prioritize verification and remediation efforts to prevent exploitation. The vulnerability is caused by a lack of verification for incoming payment notifications, which can be forged by unauthenticated attackers.
- Vendor
- Airwallex
- Product
- Online Payments Gateway
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for WordPress sites using the Airwallex Online Payments Gateway plugin should assess exposure and prioritize verification and remediation efforts to prevent potential financial losses. This includes verifying the authenticity of payment notifications, upgrading to version 1.36.0 or later, and monitoring payment notifications for suspicious activity. Additionally, defenders should review compensating controls for exposed systems and
Why it matters
CVE-2026-103517 allows unauthenticated attackers to bypass payment verification, potentially leading to financial losses. Defenders should prioritize verification and remediation.
- Unauthenticated attackers can forge payment notifications
- Orders can be marked as paid without actual payment
- Defenders must verify payment notification authenticity
- Remediation priority is high for sites using affected versions
Technical summary
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. The vulnerability is caused by a lack of verification for incoming payment notifications, which can be forged by unauthenticated attackers. This can lead to financial losses if exploited. Defenders should prioritize verifying the authenticity of payment notifications and upgrading to version 1.36.0 or later.
Defensive priority
Defenders should prioritize verifying the authenticity of payment notifications and upgrading to version 1.36.0 or later.
Recommended defensive actions
- Verify the authenticity of payment notifications
- Upgrade to version 1.36.0 or later
- Monitor payment notifications for suspicious activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Plan vendor-supported updates or mitigations through normal change control
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploitation or affected systems. The vulnerability has been publicly disclosed, and defenders should verify the authenticity of payment notifications and upgrade to version 1.36.0 or later. The source item provides technical details on the vulnerability, but additional information on affected systems and potential exploitation is needed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Webhook
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103517.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/17179c6d-32e0-4a22-88b4-9768a5f36365/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.