Impact
The vulnerability allows an attacker to send forged Stripe webhook events to the WordPress site without the need for authentication. Because the plugin’s webhook handler bypasses the required cryptographic signature check when the signing secret is unset, the raw POST body is treated as a legitimate Stripe event. This can lead to arbitrary manipulation of order status, including marking unpaid orders as paid, completing payments that never occurred, forcing successful orders into a failed state, fabricating dispute notifications, or injecting forged refund events. The weakness is an improper verification of cryptographic signature (CWE-347).
Affected Systems
WordPress sites running the Payment Gateway of Stripe for WooCommerce plugin version five point zero point eight or older are vulnerable. Any site that has not configured the Stripe webhook signing secret in the plugin’s settings is exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation is possible when the offending endpoint is publicly reachable, the signing secret is empty, and the attacker can issue unauthenticated HTTP POST requests. Once a valid signing secret is configured, the constructed Stripe event fails signature verification and the attack vector is closed, limiting risk to sites with misconfigured or unconfigured secrets.
OpenCVE Enrichment