CVE-2026-73314 | XenForo up to 2.3.12 PayPal REST Webhook auth_algo signature verification
A vulnerability labeled as problematic has been found in XenForo up to 2.3.12. Impacted is an unknown function of the component PayPal REST Webhook Handler. The manipulation of the argument auth_algo results in improper verification of cryptographic signature.
This vulnerability is reported as CVE-2026-73314. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More