HIGH
Sylius
CVE published 2026-07-30
CVE-2026-68500
The Sylius Mollie Plugin, used for integrating Mollie payment gateway with Sylius applications, contains a vulnerability. Specifically, the POST /{_locale}/update-payment payment webhook does not verify that the Mollie payment belongs to the referenced Sylius order. This oversight allows an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring f [truncated]