Security Flaw in Payment Plugins for Stripe WooCommerce by WordPress
CVE-2026-80339
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-80339?
A security flaw in the Payment Plugins for Stripe WooCommerce WordPress plugin prior to version 4.0.12 allows unauthenticated users to access sensitive billing information. This vulnerability arises from insufficient validation of the order key, which enables attackers to iterate through order identifiers and extract private order data directly from the front-end JavaScript configuration. Consequently, unauthorized access to critical information such as billing details can result, posing a significant risk to users and their transactions.
Affected Version(s)
Payment Plugins for Stripe WooCommerce 4.0.0 < 4.0.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.