Multiple security vulnerabilities have been identified in sylius/mollie-plugin, a package used for payment processing in Sylius. The overall risk/impact is moderate to high due to potential unauthorized access and data exposure. Affected version range is 2.2.8 and below.
CVE-2026-68500 (CVSS 7.5 — High): The sylius/mollie-plugin is vulnerable to payment status forgery via the payment webhook, allowing an attacker to manipulate payment information. An authenticated attacker with access to the payment webhook can exploit this vulnerability.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in sylius/mollie-plugin, a package used for payment processing in Sylius. The overall risk/impact is moderate to high due to potential unauthorized access and data exposure. Affected version range is 2.2.8 and below.
CVE-2026-68500 (CVSS 7.5 — High): The sylius/mollie-plugin is vulnerable to payment status forgery via the payment webhook, allowing an attacker to manipulate payment information. An authenticated attacker with access to the payment webhook can exploit this vulnerability.[emaillocker id="1283"]
CVE-2026-68501: The sylius/mollie-plugin has an unauthenticated IDOR that leaks order token and customer PII, enabling an attacker to obtain sensitive user data. This vulnerability can be exploited by an unauthorized user accessing the affected system.
These vulnerabilities collectively present a significant risk to administrators who have not applied updates.
We recommend you to update Sylius Mollie Plugin to version 2.2.8 or 3.2.4 or 3.3.1.
The following reports contain further technical details:
[/emaillocker]