---
id: CVE-2026-103517
title: >-
  The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not
  verify that an incoming payment notification genuinely comes from the payment
  provider when no webhook secret has been configured, allowing unauthenticated
  att…
summary: >-
  The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not
  verify that an incoming payment notification genuinely comes from the payment
  provider when no webhook secret has been configured, allowing unauthenticated
  att…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-345
product: Airwallex Online Payments Gateway
affected:
  - airwallex_online_payments_gateway < 1.36.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:51:18.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103517'
references:
  - url: 'https://wpscan.com/vulnerability/17179c6d-32e0-4a22-88b4-9768a5f36365/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T10:54:05.834329Z'
ingestedAt: '2026-10-08T11:31:27.688Z'
---

## Overview

The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
