Junglewise Threat Intelligence

CVE-2026-57635: FunnelKit Payment Gateway for Stripe WooCommerce CSRF

CVE-2026-57635 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Vendors: FunnelKit.

Executive brief

FunnelKit Payment Gateway for Stripe WooCommerce is a WordPress plugin used to process credit card payments via Stripe. A security flaw exists where an attacker can trick an administrator into performing unintended actions on the site, such as changing payment settings. This could lead to unauthorized configuration changes that disrupt business operations or redirect payment flows.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the FunnelKit Payment Gateway for Stripe WooCommerce plugin for WordPress due to insufficient nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into clicking a specially crafted link or visiting a malicious webpage. If successful, the attacker can force the administrative user to execute unintended state-changing actions within the plugin's configuration. The vulnerability is present in versions up to and including 1.14.0.3 and is resolved in version 1.14.0.4.

Affected products

  • FunnelKit FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3

Timeline

  • 2026-05-07: other: Reported by ParkHyunWoo
  • 2026-06-26: disclosed: Published by Patchstack
  • 2026-06-26: patched: Version 1.14.0.4 released

References