Junglewise Threat Intelligence

CVE-2026-11462: Chengdu Everbrite BeikeShop improper authorization in Stripe Plugin

CVE-2026-11462 · Severity: high · CVSS 7.3 · Published 2026-06-07

Executive brief

BeikeShop, an e-commerce platform, contains a security flaw in its Stripe payment plugin. This vulnerability allows an attacker to bypass the payment process by sending fake payment confirmation messages to the store. As a result, malicious users could mark orders as paid and receive goods or services without actually completing a transaction, leading to direct financial loss for the merchant.

Technical details

An improper authorization vulnerability exists in the Stripe plugin of BeikeShop up to version 1.6.0.22. The root cause is a missing signature verification in the `callback` function within `plugins/Stripe/Controllers/StripeController.php`. The application processes incoming webhook events from the `/callback/stripe` endpoint without validating the `Stripe-Signature` header. A remote, unauthenticated attacker can exploit this by sending a forged `charge.succeeded` JSON payload containing a valid order number, causing the system to incorrectly transition the order status to 'PAID'. A patch has been released in commit 6719e0fc690ea0a998452092862e0f0a17c65968.

Affected products

  • Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22

Timeline

  • 2026-06-04: patched: Patch commit 6719e0fc690ea0a998452092862e0f0a17c65968 released.
  • 2026-06-07: disclosed: Vulnerability published to NVD.

References

Related threats