WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter
mediumThe WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment...
- CVSS:
- 6.5
- Affected:
- up to 10.7.0
- Fixed in:
- 10.8.0
- Disclosed:
- Jun 15, 2026