Executive brief
The pretix-mollie plugin, used for processing payments in the pretix ticketing system, failed to properly verify payment confirmation messages. An attacker could reuse a single successful payment confirmation to trick the system into issuing multiple tickets for different orders. This could lead to financial loss for event organizers as users obtain valid tickets without paying for them.
Technical details
The vulnerability is classified as CWE-841 (Improper Enforcement of Behavioral Workflow) within the pretix-mollie plugin. The root cause is insufficient validation of payment status responses from the Mollie payment gateway. An attacker can capture a valid 'success' response from one transaction and replay or supply it to the system for a different, unpaid transaction. This allows the attacker to bypass the payment requirement for subsequent tickets. The vulnerability is fixed in pretix-mollie version 2.5.6.
Affected products
- pretix pretix-mollie < 2.5.6
Timeline
- 2026-06-25: disclosed: Discovered internally by the pretix team.
- 2026-06-25: advisory
- 2026-06-25: patched: Fixed in version 2.5.6.