CVE-2026-33661 | yansongda pay up to 3.7.19 WeChat Pay Callback Endpoint src/Functions.php verify_wechat_sign authentication spoofing
A vulnerability identified as critical has been detected in yansongda pay up to 3.7.19. Affected by this vulnerability is the function verify_wechat_sign of the file src/Functions.php of the component WeChat Pay Callback Endpoint. The manipulation leads to authentication bypass by spoofing.
This vulnerability is referenced as CVE-2026-33661. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.