Improper Verification of Cryptographic Signature in Payment Gateway for WooCommerce by Stripe
CVE-2026-9832
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-9832?
The Payment Gateway for WooCommerce plugin by Stripe is susceptible to an issue where the verification of cryptographic signatures is improperly handled. This vulnerability stems from the default installation configuration, which leaves the critical eh_stripe_webhook_secret option empty. As a result, the webhook endpoint processes incoming requests without signature verification, allowing unauthenticated attackers to forge webhook events. This could lead to unauthorized manipulation of WooCommerce order statuses, potentially marking unpaid orders as paid, fabricating disputes, or injecting fake refund notifications. Administrators must ensure the proper configuration of the Stripe webhook signing secret to mitigate this risk and enforce verification.
Affected Version(s)
Payment Gateway of Stripe for WooCommerce 0 <= 5.0.8