Cross-Site Request Forgery Vulnerability in PeachPay for WooCommerce
CVE-2026-9618
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 May 2026
What is CVE-2026-9618?
The PeachPay for WooCommerce plugin, present in all versions up to and including 1.120.46, is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the peachpay_stripe_handle_admin_actions function. This flaw allows unauthorized attackers to exploit CSRF, enabling them to delete sensitive Stripe payment credentials — such as publishable keys, secret keys, and webhook secrets — from the WordPress database. Consequently, a malicious actor could disrupt Stripe payment processing by tricking an administrator into executing a harmful action, thus jeopardizing the store’s transaction capabilities.
Affected Version(s)
PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) 0 <= 1.120.46