Unauthenticated CSRF Vulnerability in FunnelKit Payment Gateway for Stripe
CVE-2026-57635

6.5MEDIUM

What is CVE-2026-57635?

The FunnelKit Payment Gateway for Stripe has a vulnerability that allows unauthenticated attackers to execute cross-site request forgery (CSRF) attacks. This specifically affects versions 1.14.0.3 and earlier, potentially enabling malicious users to perform unauthorized actions on behalf of authenticated users without their consent. It is crucial for users of this plugin to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ParkHyunWoo | Patchstack Bug Bounty Program
.