Authorization Bypass in Payment Plugins for Stripe WooCommerce by WordPress
CVE-2026-12654
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-12654?
The Payment Plugins for Stripe WooCommerce plugin for WordPress has a security flaw that allows unauthorized users to manipulate order statuses. The vulnerability arises from inadequate authorization checks, which permit unauthenticated attackers to mark WooCommerce orders as paid. This is achievable by simulating a charge.pending event with user-defined transaction details. The risk is heightened when merchants leave the webhook_secret_test or webhook_secret_live configurations empty, as this is the default setting. Once a valid secret is configured, signature verification is enforced, mitigating the risk.
Affected Version(s)
Payment Plugins for Stripe WooCommerce 0 <= 4.0.7