CVE-2026-73316 | XenForo up to 2.3.12 PayPal REST Payment Provider authentication replay

SecurityVulns

A vulnerability classified as critical was found in XenForo up to 2.3.12. This impacts an unknown function of the component PayPal REST Payment Provider. Executing a manipulation can lead to authentication bypass by capture-replay.

This vulnerability is handled as CVE-2026-73316. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More