Security Flaw in Payment Plugins for Stripe WooCommerce by WordPress
CVE-2026-80339

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80339?

A security flaw in the Payment Plugins for Stripe WooCommerce WordPress plugin prior to version 4.0.12 allows unauthenticated users to access sensitive billing information. This vulnerability arises from insufficient validation of the order key, which enables attackers to iterate through order identifiers and extract private order data directly from the front-end JavaScript configuration. Consequently, unauthorized access to critical information such as billing details can result, posing a significant risk to users and their transactions.

Affected Version(s)

Payment Plugins for Stripe WooCommerce 4.0.0 < 4.0.12

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

m1w34p0n
WPScan
.