Compatible XF Versions
  1. 2.1
Today, we are releasing XenForo 2.1.9 and XenForo 2.0.13 to address a potential security vulnerability that may affect any customer who makes use of our PayPal payment handler.

As well as user upgrades, this may affect add-ons you have installed which process payments using our PayPal payment handler.

We recommend that all affected customers running XenForo 2.1 or XenForo 2.0 upgrade to 2.1.9 or 2.0.13 or use one of the attached patch files as soon as possible.

Specifically, the issue relates to a specially crafted callback (or IPN) which is then processed successfully using PayPal's sandbox validation endpoint instead of their live system. If successful, a purchase could be completed without your PayPal account actually receiving any funds.

There are no other fixes included in this version. There will be a further 2.1 maintenance release in the coming weeks.
Author
Admin
Size
12.3 MB
Extension
zip
Downloads
14
Views
2,888
First release
Last update

More resources from Admin

Similar resources

XenForo Full AnimeHaxor
Released (Unsupport) XenForo Full 2.0.0 beta 4 Nulled
XenForo - Full (Unsupported) 2.0.0 beta 4
0.00 star(s) 0 ratings
Downloads
28
Updated
XenForo Full Admin
xF2 Released XenForo Full 2.2.5 Nulled
XenForo 2.2.5 Full Nulled By NulledTeam
0.00 star(s) 0 ratings
Downloads
8
Updated
XenForo Full Admin
  • Featured
xF2 Released XenForo Full 2.2.15 Nulled
XenForo 2.2.14 Upgrade Nulled By null-scripts.net
0.00 star(s) 0 ratings
Downloads
9
Updated
XenForo Full Admin
xF2 Released XenForo Full 2.2.2 Nulled
XenForo 2.2.2 Full Nulled By NulledTeam
5.00 star(s) 1 ratings
Downloads
10
Updated
XenForo Full Admin
xF2 Released XenForo Full 2.0.1 Nulled
XenForo 2.0.1 - Full Nulled By NulledTeam
0.00 star(s) 0 ratings
Downloads
302
Updated