
🟠 CVE-2026-33661 - High Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally s... https://www.thehackerwire.com/vulnerability/CVE-2026-33661/ https://t.co/eiTp5K1Bb5
Post summary
CVE-2026-33661 is a high‑severity flaw in the Pay SDK’s verify_wechat_sign() function, fixed in version 3.7.20. No PoC, exploit code, or active exploitation details are provided.


