CVE-2026-44583 | Paymenter up to 1.4.x PayPal webhook endpoint file_get_contents PAYPAL-CERT-URL server-side request forgery

SecurityVulns

A vulnerability marked as critical has been reported in Paymenter up to 1.4.x. Affected by this issue is the function file_get_contents of the file /extensions/paypal/webhook of the component PayPal webhook endpoint. This manipulation of the argument PAYPAL-CERT-URL causes server-side request forgery.

This vulnerability is registered as CVE-2026-44583. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More