THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rc52-c4hv-w89p (high) — Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook

[GHSA] GHSA-rc52-c4hv-w89p (high) — Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook

medgithub_advisoriesPublished 2026-07-31

GHSA-rc52-c4hv-w89p Severity: high CVE: CVE-2026-68500

Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook

### Impact The shop payment webhook `POST /{_locale}/update-payment` (route `sylius_mollie_shop_payment_webhook`) accepts two independent, attacker-controlled parameters: `id` (the Mollie payment ID, verified against Mollie's API) and `orderId` (the Syl

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rc52-c4hv-w89p