
Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.
XenForo before 2.3.13 fetches the certificate URL supplied by a PayPal REST webhook without restricting its destination.
The callback handler passes PAYPAL-CERT-URL to XenForo's trusted HTTP reader. It does not require a PayPal hostname and does not block loopback or private-network destinations. A remote request can therefore make the XenForo host fetch an attacker-selected URL.
I confirmed the SSRF with a listener on XenForo 2.3.12. I also tested the signature path with a synthetic certificate and the configured webhook ID. That second result requires knowledge of the webhook ID.
The demonstrated impact is blind server-side HTTP(S) access. Payment forgery is conditional on additional configuration knowledge. XenForo 2.3.13 contains the fix.
The script signs one synthetic callback with a local test key and points the certificate header at a URL you control:
python poc.py https://xenforo.example REQUEST_KEY 10.00 USD TEST_WEBHOOK_ID https://listener.example/test-cert.pem test-key.pem
The listener must serve the certificate matching test-key.pem.
Discovered by Marco Paciaroni (BomboBombone).