Executive brief
The PeachPay plugin for WooCommerce, which handles various payment methods like Stripe and PayPal, contains a security flaw that could allow an attacker to disrupt store operations. By tricking a site administrator into clicking a malicious link, an attacker can remotely delete the store's Stripe payment credentials. This would immediately disable Stripe payment processing for the online store, potentially leading to lost revenue and operational downtime.
Technical details
The PeachPay plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'peachpay_stripe_handle_admin_actions' function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request. Successful exploitation allows the attacker to permanently delete stored Stripe credentials, including secret keys, webhook secrets, and Apple Pay configurations, from the WordPress database. This effectively disables Stripe payment processing for the affected WooCommerce store. The vulnerability is present in all versions up to and including 1.120.46.
Affected products
- PeachPay PeachPay — Payments & Express Checkout for WooCommerce up to, and including, 1.120.46
Timeline
- 2026-05-28: disclosed: Initial publication of the CVE record.
- 2026-05-28: advisory: NVD and Wordfence published advisory details.
References
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.23/core/admin/settings.php
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.23/core/payments/stripe/functions.php
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.23/core/payments/stripe/functions.php
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.45/core/admin/settings.php
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.45/core/payments/stripe/functions.php
- https://plugins.trac.wordpress.org/browser/peachpay-for-woocommerce/tags/1.120.45/core/payments/stripe/functions.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3550723%40peachpay-for-woocommerce&new=3550723%40peachpay-for-woocommerce&sfp_email=&sfph_mail=