Sceawere
Vulnerability Detail
CVE-2026-103517UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Airwallex Plugin Webhook Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- Airwallex Online Payments Gateway
- Attack Type
- CWE-345 Insufficient Verification of Data Authenticity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-08T11:16:42.613Z",
"pubdate": "2026-10-08T11:16:42.613Z",
"executiveSummary": "The Airwallex Online Payments Gateway WordPress plugin, in versions prior to 1.36.0, contains a critical authentication bypass vulnerability related to improper verification of payment notification origins.\nThe vulnerability arises when a webhook secret has not been configured by the site administrator, resulting in the absence of signature validation for incoming callbacks.\nThis flaw allows unauthenticated remote attackers to forge malicious payment notifications that the plugin incorrectly interprets as valid confirmation from the Airwallex payment gateway.\nBy crafting a spoofed request, an attacker can programmatically update the status of arbitrary orders to 'paid' within the WordPress database without actually completing a financial transaction.\nThe risk implication is severe, as it facilitates direct financial fraud and inventory loss for e-commerce merchants. Exploitation does not require prior authentication or privileged access to the WordPress environment, as the vulnerable callback endpoint is publicly exposed.\nImmediate remediation is required by updating the plugin to version 1.36.0 or higher and ensuring that a webhook secret is properly configured to enforce cryptographic request verification.",
"technicalDetails": "The vulnerability is rooted in the plugin's webhook handling mechanism, which fails to enforce strict cryptographic verification of incoming notifications when the 'webhook secret' configuration parameter is omitted.\nIn a secure implementation, an integration should verify the authenticity of a webhook request by computing an HMAC signature of the payload using a shared secret and comparing it against the signature provided in the request headers (typically 'x-webhook-signature').\nIn the affected versions of the Airwallex Online Payments Gateway plugin, the logic responsible for this handshake is conditional. If the administrator fails to define a secret key in the plugin settings, the code path governing signature validation is bypassed entirely.\nThe attack flow begins with an attacker identifying the endpoint exposed by the plugin for handling Airwallex notifications. Since the endpoint does not authenticate the source, the attacker can submit a crafted HTTP POST request to this URL.\nThe forged request mimics the structure of an official Airwallex webhook notification. The payload contains data structured to indicate a successful payment for a specific order ID existing within the victim's WordPress instance.\nUpon receiving the request, the plugin parses the JSON payload. Due to the lack of a required webhook secret, the plugin omits the signature verification step, erroneously treating the payload as an authoritative notification transmitted by Airwallex.\nThe plugin proceeds to trigger its order processing routines, which include updating the order status to 'paid' within the WooCommerce (or relevant e-commerce) order management system.\nPost-exploitation impact includes the potential for attackers to gain physical or digital goods without financial remuneration. The attack is entirely network-based and exploits the trust relationship between the merchant's server and the payment gateway.\nBecause the plugin does not enforce an 'all-or-nothing' security posture regarding secrets, it defaults to an insecure state. Any installation where the webhook secret is empty or incorrectly configured is vulnerable to arbitrary order status manipulation by any remote actor capable of sending a correctly formatted HTTP request to the webhook URL."
}