Executive brief
XenForo is a popular forum and community platform that handles user subscriptions and account upgrades through payment integrations. A vulnerability in the PayPal payment processor allows attackers who intercept a legitimate payment webhook to replay it multiple times, causing duplicate charges, repeated subscription activations, and unauthorized account upgrades. This could result in financial fraud and unauthorized service access for affected users.
Technical details
The PayPal REST payment provider in XenForo overrides the base validateTransaction() method but omits the duplicate transaction-log lookup that the parent implementation performs. Additionally, the database index for transaction IDs is non-unique, allowing duplicate entries. An attacker with access to a valid, signed webhook payload can resend it multiple times; each replay passes signature verification and triggers purchase completion without checking if the provider event has already been processed. This results in multiple payment log entries and repeated subscription extensions. The vulnerability affects XenForo versions before 2.3.13 and requires the attacker to capture an authentic webhook callback but does not require forging signatures. Version 2.3.13 adds transaction replay protection to prevent this issue.
Affected products
- XenForo XenForo before 2.3.13
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: XenForo 2.3.13 released with transaction replay protection