Impact
The Payment Plugins for Stripe WooCommerce WordPress plugin, in versions before 4.0.12, fails to validate the order key before exposing order data through a JavaScript configuration rendered on the frontend. This flaw allows an unauthenticated attacker to iteratively guess sequential order identifiers and retrieve the full billing details of any order along with the secret that protects that order. The disclosed information compromises customer privacy and may include sensitive payment information, thereby violating confidentiality.
Affected Systems
This vulnerability affects installations of the Payment Plugins for Stripe WooCommerce plugin for WordPress, any version lower than 4.0.12. Users of older plugin releases should verify their installed version and consider upgrading.
Risk and Exploitability
The flaw can be leveraged by anyone with internet access to the site because authentication is not required. Because the adversary can enumerate orders sequentially, the attack surface is relatively high if the site hosts many orders. The CVSS score of 5.3 indicates a medium severity, reflecting the potential for privacy compromise. The EPSS score of less than 1% and the absence of a KEV listing do not diminish the importance of remediation, as the ability to iterate order identifiers does not require sophistication or specialized tooling. The attack vector is inferred to be a simple HTTP request to the order‑pay endpoint, which the plugin automatically renders on the frontend.
OpenCVE Enrichment