Junglewise Threat Intelligence

CVE-2026-45217: ThemeHigh Stripe Payment Gateway for WooCommerce authentication bypass

CVE-2026-45217 · Severity: medium · CVSS 6.5 · Published 2026-05-25

Executive brief

The Stripe Payment Gateway for WooCommerce plugin, which enables credit card payments on WordPress e-commerce sites, contains a security flaw in its authentication process. An attacker can bypass standard security checks to exploit the password recovery mechanism. This could lead to unauthorized access to user accounts or administrative control of the online store, potentially compromising customer data and business operations.

Technical details

An Authentication Bypass Using an Alternate Path or Channel (CWE-288) exists in the ThemeHigh Stripe Payment Gateway for WooCommerce plugin through version 5.0.7. The vulnerability resides in the password recovery logic, allowing unauthenticated remote attackers to bypass standard authentication protocols. By exploiting this alternate path, an attacker can potentially gain unauthorized access to user accounts, including those with elevated privileges. The issue is resolved in version 5.0.8.

Affected products

  • ThemeHigh Stripe Payment Gateway for WooCommerce n/a through 5.0.7

Timeline

  • 2026-03-24: other: Reported by Jakub Herman
  • 2026-05-12: advisory: Patchstack advisory published
  • 2026-05-25: disclosed: CVE published to NVD
  • 2026-05-12: patched: Version 5.0.8 released

References