THREAT OPS › Threat News › [GHSA] GHSA-rc52-c4hv-w89p (high) — Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
[GHSA] GHSA-rc52-c4hv-w89p (high) — Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
GHSA-rc52-c4hv-w89p Severity: high CVE: CVE-2026-68500
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
### Impact The shop payment webhook `POST /{_locale}/update-payment` (route `sylius_mollie_shop_payment_webhook`) accepts two independent, attacker-controlled parameters: `id` (the Mollie payment ID, verified against Mollie's API) and `orderId` (the Syl
Indicators of compromise
- CVE-2026-68500cve
Original source: https://github.com/advisories/GHSA-rc52-c4hv-w89p