Description
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Webhook Forgery
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker to send forged Stripe webhook events to the WordPress site without the need for authentication. Because the plugin’s webhook handler bypasses the required cryptographic signature check when the signing secret is unset, the raw POST body is treated as a legitimate Stripe event. This can lead to arbitrary manipulation of order status, including marking unpaid orders as paid, completing payments that never occurred, forcing successful orders into a failed state, fabricating dispute notifications, or injecting forged refund events. The weakness is an improper verification of cryptographic signature (CWE-347).

Affected Systems

WordPress sites running the Payment Gateway of Stripe for WooCommerce plugin version five point zero point eight or older are vulnerable. Any site that has not configured the Stripe webhook signing secret in the plugin’s settings is exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation is possible when the offending endpoint is publicly reachable, the signing secret is empty, and the attacker can issue unauthenticated HTTP POST requests. Once a valid signing secret is configured, the constructed Stripe event fails signature verification and the attack vector is closed, limiting risk to sites with misconfigured or unconfigured secrets.

Generated by OpenCVE AI on September 19, 2026 at 23:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Payment Gateway of Stripe for WooCommerce plugin to the latest version that includes the proper signature verification guard
  • Configure the Stripe webhook signing secret via the WooCommerce admin interface to ensure \Stripe\Webhook::constructEvent() enforces signature checks
  • Verify that the "eh_stripe_webhook_secret" option is no longer empty in the plugin settings and optionally restrict the webhook endpoint to known Stripe IP addresses to reduce exposure
  • Monitor order status changes and examine webhook logs for any signatures that fail verification to detect potential abuse

Generated by OpenCVE AI on September 19, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.7/includes/class-eh-stripe-webhook-handler.php#L18 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.7/includes/class-eh-stripe-webhook-handler.php#L321 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.7/includes/class-eh-stripe-webhook-handler.php#L66 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.7/includes/class-eh-stripe-webhook-handler.php#L93 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.8/includes/class-eh-stripe-webhook-handler.php#L18 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.8/includes/class-eh-stripe-webhook-handler.php#L321 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.8/includes/class-eh-stripe-webhook-handler.php#L66 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/payment-gateway-stripe-and-woocommerce-integration/tags/5.0.8/includes/class-eh-stripe-webhook-handler.php#L93 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3575195%40payment-gateway-stripe-and-woocommerce-integration&new=3575195%40payment-gateway-stripe-and-woocommerce-integration cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/2cef154c-efb8-4455-9be6-e3cf8b95e9d3?source=cve cve-icon cve-icon
History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Themehigh
Themehigh stripe Payment Gateway For Woocommerce
Wordpress-extensions
Wordpress-extensions payment Gateway Of Stripe For Woocommerce
Vendors & Products Themehigh
Themehigh stripe Payment Gateway For Woocommerce
Wordpress-extensions
Wordpress-extensions payment Gateway Of Stripe For Woocommerce

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected.
Title Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Themehigh Stripe Payment Gateway For Woocommerce
Wordpress-extensions Payment Gateway Of Stripe For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:24.308Z

Reserved: 2026-05-28T12:34:29.054Z

Link: CVE-2026-9832

cve-icon Vulnrichment

Updated: 2026-09-19T13:54:22.290Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:55.340

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:08Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature