Cross-Site Request Forgery Vulnerability in PeachPay for WooCommerce
CVE-2026-9618

4.3MEDIUM

What is CVE-2026-9618?

The PeachPay for WooCommerce plugin, present in all versions up to and including 1.120.46, is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the peachpay_stripe_handle_admin_actions function. This flaw allows unauthorized attackers to exploit CSRF, enabling them to delete sensitive Stripe payment credentials — such as publishable keys, secret keys, and webhook secrets — from the WordPress database. Consequently, a malicious actor could disrupt Stripe payment processing by tricking an administrator into executing a harmful action, thus jeopardizing the store’s transaction capabilities.

Affected Version(s)

PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) 0 <= 1.120.46

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Benedictus Jovan
.