Executive brief
The Stripe For WooCommerce plugin, which enables WordPress sites to accept payments via Stripe, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. This could potentially allow an attacker to interfere with payment processing or modify order-related data without needing to log in. Such an exploit could disrupt business operations and impact the integrity of transaction records.
Technical details
The Stripe For WooCommerce plugin (woo-stripe-payment) for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to 4.0.7. This vulnerability allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is on data integrity, suggesting that an attacker could modify information without authorization. The issue is resolved in version 4.0.8.
Affected products
- Payment Plugins Stripe For WooCommerce <= 4.0.7
Timeline
- 2026-02-22: other: Reported by researcher timomangcut
- 2026-07-23: advisory: Patchstack published advisory
- 2026-07-27: disclosed: CVE published to NVD