Description
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.
Published: 2026-07-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Payment Plugins for Stripe WooCommerce allows unauthenticated attackers to impersonate the Stripe webhook when the plugin’s webhook secret options are left blank. The plugin fails to verify that the request originates from a legitimate source, enabling the attacker to send a fabricated charge.pending event containing an arbitrary order_id, gateway_id and a charge object with status=succeeded and captured=true. This triggers the payment_complete() routine and downstream fulfillment, effectively marking the order as paid with the attacker‑supplied transaction ID. The weakness is an authorization bypass (CWE‑862).

Affected Systems

All releases of the Payment Plugins for Stripe WooCommerce plugin up to and including version 4.0.7 are affected when the webhook_secret_test or webhook_secret_live fields are left empty. The plugin is available for WordPress installations using WooCommerce; any site that has installed a vulnerable version with default (blank) webhook secrets is vulnerable.

Risk and Exploitability

With a CVSS score of 5.3, the flaw is considered moderate severity. The EPSS score is below 1 %, indicating that the probability of exploitation is low, yet the vulnerability exists in the plugin’s default configuration, which many merchants may leave unchanged. The flaw is not listed in CISA’s KEV catalog, reducing its prominence in known exploit databases. Attackers who succeed can cause financial loss by making orders appear paid without authorization, potentially triggering shipping and invoicing.

Generated by OpenCVE AI on August 3, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Payment Plugins for Stripe WooCommerce plugin to the latest released version (≥4.0.8).
  • Configure a valid webhook_secret_test and webhook_secret_live value to enable signature verification.
  • Restrict access to the webhook endpoint to authorized IP ranges or disable unprotected webhooks if unused.

Generated by OpenCVE AI on August 3, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/abstract/abstract-wc-stripe-payment.php#L104 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L24 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L54 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/controllers/class-wc-stripe-controller-webhook.php#L60 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.105/includes/wc-stripe-webhook-functions.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/abstract/abstract-wc-stripe-payment.php#L104 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L24 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L54 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/controllers/class-wc-stripe-controller-webhook.php#L60 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/woo-stripe-payment/tags/3.3.108/includes/wc-stripe-webhook-functions.php#L427 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3611878%40woo-stripe-payment&new=3611878%40woo-stripe-payment cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/45185f25-9a1f-411d-9d2a-295b5ceb5629?source=cve cve-icon cve-icon
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Payment Plugins
Payment Plugins payment Plugins For Stripe Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Payment Plugins
Payment Plugins payment Plugins For Stripe Woocommerce
Wordpress
Wordpress wordpress

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.
Title Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Payment Plugins Payment Plugins For Stripe Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-24T19:55:36.258Z

Reserved: 2026-06-18T18:47:59.973Z

Link: CVE-2026-12654

cve-icon Vulnrichment

Updated: 2026-07-24T19:55:17.343Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T08:16:25.623

Modified: 2026-07-24T20:45:45.697

Link: CVE-2026-12654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses