Improper Verification of Cryptographic Signature in Payment Gateway for WooCommerce by Stripe
CVE-2026-9832

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-9832?

The Payment Gateway for WooCommerce plugin by Stripe is susceptible to an issue where the verification of cryptographic signatures is improperly handled. This vulnerability stems from the default installation configuration, which leaves the critical eh_stripe_webhook_secret option empty. As a result, the webhook endpoint processes incoming requests without signature verification, allowing unauthenticated attackers to forge webhook events. This could lead to unauthorized manipulation of WooCommerce order statuses, potentially marking unpaid orders as paid, fabricating disputes, or injecting fake refund notifications. Administrators must ensure the proper configuration of the Stripe webhook signing secret to mitigate this risk and enforce verification.

Affected Version(s)

Payment Gateway of Stripe for WooCommerce 0 <= 5.0.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pradeep suvarna
.