Authorization Bypass in Payment Plugins for Stripe WooCommerce by WordPress
CVE-2026-12654

5.3MEDIUM

What is CVE-2026-12654?

The Payment Plugins for Stripe WooCommerce plugin for WordPress has a security flaw that allows unauthorized users to manipulate order statuses. The vulnerability arises from inadequate authorization checks, which permit unauthenticated attackers to mark WooCommerce orders as paid. This is achievable by simulating a charge.pending event with user-defined transaction details. The risk is heightened when merchants leave the webhook_secret_test or webhook_secret_live configurations empty, as this is the default setting. Once a valid secret is configured, signature verification is enforced, mitigating the risk.

Affected Version(s)

Payment Plugins for Stripe WooCommerce 0 <= 4.0.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gidget smith
.