Authorization Bypass Through User-Controlled Key Affecting sylius/mollie-plugin package, versions <2.2.8>=3.0.0, <3.2.4>=3.3.0, <3.3.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SYLIUSMOLLIEPLUGIN-18506885
  • published2 Aug 2026
  • disclosed31 Jul 2026
  • creditUnknown

Introduced: 31 Jul 2026

NewCVE-2026-68501  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade sylius/mollie-plugin to version 2.2.8, 3.2.4, 3.3.1 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the thankYouAction and fetchQrCodeFromOrder endpoints, which allow unauthenticated access to order information based on a sequential integer identifier without verifying ownership or session. An attacker can obtain sensitive customer data, such as order tokens and personally identifiable information, by enumerating order identifiers and leveraging the exposed token to access pre-filled registration forms.

Workaround

This vulnerability can be mitigated by decorating the affected controllers to enforce ownership checks before processing requests, as detailed in the advisory.

CVSS Base Scores

version 4.0
version 3.1