CVE-2026-33661 describes a critical vulnerability in the Pay open-source payment SDK, prior to version 3.7.20, where the `verify_wechat_sign()` function unconditionally skips signature verification if the host is reported as 'localhost'. Rated 8.6 HIGH (CVSS), this flaw allows an unauthenticated attacker to forge fake WeChat Pay success notifications by sending a crafted HTTP request with a `Host: localhost` header, causing applications to mark orders as paid without actual payment. Despite no confirmed active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), its low attack complexity and network vector present a significant risk, with recent community discussions indicating awareness. Organizations using affected versions should prioritize upgrading to version 3.7.20.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.7.20CPE matchmatch criteria | cpe:2.3:a:yansongda:pay:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.