Unauthenticated CSRF Vulnerability in FunnelKit Payment Gateway for Stripe
CVE-2026-57635
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 June 2026
What is CVE-2026-57635?
The FunnelKit Payment Gateway for Stripe has a vulnerability that allows unauthenticated attackers to execute cross-site request forgery (CSRF) attacks. This specifically affects versions 1.14.0.3 and earlier, potentially enabling malicious users to perform unauthorized actions on behalf of authenticated users without their consent. It is crucial for users of this plugin to update to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3