Executive brief
BeikeShop, an e-commerce platform, contains a security flaw in its Stripe payment plugin. This vulnerability allows an attacker to bypass the payment process by sending fake payment confirmation messages to the store. As a result, malicious users could mark orders as paid and receive goods or services without actually completing a transaction, leading to direct financial loss for the merchant.
Technical details
An improper authorization vulnerability exists in the Stripe plugin of BeikeShop up to version 1.6.0.22. The root cause is a missing signature verification in the `callback` function within `plugins/Stripe/Controllers/StripeController.php`. The application processes incoming webhook events from the `/callback/stripe` endpoint without validating the `Stripe-Signature` header. A remote, unauthenticated attacker can exploit this by sending a forged `charge.succeeded` JSON payload containing a valid order number, causing the system to incorrectly transition the order status to 'PAID'. A patch has been released in commit 6719e0fc690ea0a998452092862e0f0a17c65968.
Affected products
- Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22
Timeline
- 2026-06-04: patched: Patch commit 6719e0fc690ea0a998452092862e0f0a17c65968 released.
- 2026-06-07: disclosed: Vulnerability published to NVD.