Description
The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Patch Now
AI Analysis

Impact

The Payment Plugins for Stripe WooCommerce WordPress plugin, in versions before 4.0.12, fails to validate the order key before exposing order data through a JavaScript configuration rendered on the frontend. This flaw allows an unauthenticated attacker to iteratively guess sequential order identifiers and retrieve the full billing details of any order along with the secret that protects that order. The disclosed information compromises customer privacy and may include sensitive payment information, thereby violating confidentiality.

Affected Systems

This vulnerability affects installations of the Payment Plugins for Stripe WooCommerce plugin for WordPress, any version lower than 4.0.12. Users of older plugin releases should verify their installed version and consider upgrading.

Risk and Exploitability

The flaw can be leveraged by anyone with internet access to the site because authentication is not required. Because the adversary can enumerate orders sequentially, the attack surface is relatively high if the site hosts many orders. The CVSS score of 5.3 indicates a medium severity, reflecting the potential for privacy compromise. The EPSS score of less than 1% and the absence of a KEV listing do not diminish the importance of remediation, as the ability to iterate order identifiers does not require sophistication or specialized tooling. The attack vector is inferred to be a simple HTTP request to the order‑pay endpoint, which the plugin automatically renders on the frontend.

Generated by OpenCVE AI on September 9, 2026 at 18:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch to version 4.0.12 or newer of the Payment Plugins for Stripe WooCommerce plugin.
  • If an immediate update is not possible, block or require authentication for the order‑pay endpoint to stop unauthenticated enumeration of order identifiers.
  • Review the JavaScript configuration output on the frontend and remove any customer or billing data that should not be publicly visible.

Generated by OpenCVE AI on September 9, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers.
Title Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-pay
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:39:50.838Z

Reserved: 2026-08-26T09:19:33.772Z

Link: CVE-2026-80339

cve-icon Vulnrichment

Updated: 2026-09-09T15:34:07.690Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:16.650

Modified: 2026-09-09T16:17:09.307

Link: CVE-2026-80339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T18:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor