Executive brief
The WooCommerce Stripe Payment Gateway plugin for WordPress, which allows businesses to accept credit card payments, contains a security flaw that allows unauthorized users to interfere with customer orders. An attacker can remotely force pending orders into a 'failed' status by submitting fake payment information. This can disrupt business operations, prevent successful sales, and negatively impact the customer experience by causing legitimate transactions to be cancelled.
Technical details
The WooCommerce Stripe Payment Gateway plugin is vulnerable to an authorization bypass due to a missing capability check on the `ajax_pay_for_order()` function within the `wc_stripe_pay_for_order` WC-AJAX endpoint. While the function validates a nonce, it fails to verify order ownership or the `order_key`. This allows unauthenticated attackers to use sequential order ID enumeration and provide fake payment methods to trigger payment exceptions. These exceptions force the target order's status to 'failed'. The vulnerability is patched in version 10.8.0.
Affected products
- WooCommerce WooCommerce Stripe Payment Gateway up to, and including, 10.7.0
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
References
- https://plugins.trac.wordpress.org/browser/woocommerce-gateway-stripe/tags/10.3.1/includes/class-wc-gateway-stripe.php
- https://plugins.trac.wordpress.org/browser/woocommerce-gateway-stripe/tags/10.3.1/includes/payment-methods/class-wc-stripe-express-checkout-ajax-handler.php
- https://plugins.trac.wordpress.org/changeset/3564842/woocommerce-gateway-stripe/trunk/includes/payment-methods/class-wc-stripe-express-checkout-ajax-handler.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwoocommerce-gateway-stripe/tags/10.7.0&new_path=%2Fwoocommerce-gateway-stripe/tags/10.8.0
- https://research.cleantalk.org/cve-2026-2381
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ab3b52f7-e2c3-44f7-8e19-b6c51ccd50e0?source=cve