plugin

Woocommerce Gateway Stripe Vulnerabilities

5 known security issues reported for the Woocommerce Gateway Stripe WordPress plugin. Most recent disclosed Jun 15, 2026.

1 high 4 medium

Running Woocommerce Gateway Stripe on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

medium

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment...

CVSS:
6.5
Affected:
up to 10.7.0
Fixed in:
10.8.0
Disclosed:
Jun 15, 2026

CVE-2026-2381 on NVD →

WooCommerce Stripe Payment Gateway <= 7.6.1 - Insecure Direct Object Reference via update_payment_intent_ajax

medium

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.6.1 via the update_payment_intent_ajax due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to make updates to payment...

CVSS:
6.5
Affected:
up to 7.6.1
Fixed in:
7.6.2
Disclosed:
Dec 27, 2023

CVE-2023-51502 on NVD →

Stripe Gateway <= 7.6.0 - Cross-Site Request Forgery

medium

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 7.6.1 (exclusive). This is due to missing or incorrect nonce validation on the maybe_handle_redirect function. This makes it possible for unauthenticated attackers to change the stripe connectio...

CVSS:
5.4
Affected:
up to 7.6.1
Fixed in:
7.6.1
Disclosed:
Oct 17, 2023

CVE-2023-44999 on NVD →

WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure

high

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 7.4.0. This is due to insufficient validation in the payment_fields() and javascript_params () functions that do not properly validate order ownership. This makes it possible f...

CVSS:
7.5
Affected:
up to 5.5.0, 5.5.0 – 5.5.1, 5.6.0 – 5.6.3, 5.7.0 – 5.7.1, 5.8.0 – 5.8.2, 5.9.0 – 5.9.1, 6.0.0 – 6.0.1, 6.1.0 – 6.1.1, 6.2.0 – 6.2.1, 6.3.0 – 6.3.1, 6.4.0 – 6.4.4, 6.5.0 – 6.5.2, 6.6.0 – 6.6.1, 6.7.0 – 6.7.1, 6.8.0 – 6.8.1, 6.9.0 – 6.9.1, 7.0.0 – 7.0.3, 7.1.0 – 7.1.1, 7.2.0 – 7.2.1, 7.3.0 – 7.3.1, 7.4.0 – 7.4.0
Fixed in:
5.5.1
Disclosed:
Jun 13, 2023

CVE-2023-34000 on NVD →

WooCommerce Stripe Payment Gateway <= 7.4.0 - Missing Authorization

medium

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
6.3
Affected:
up to 7.4.0
Fixed in:
7.4.1
Disclosed:
Jun 13, 2023

CVE-2023-35049 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database