WordPress · Payment Gateway Of Stripe For Woocommerce · CVE-2026-9832
**Name of the Vulnerable Software and Affected Versions**
Payment Gateway of Stripe for WooCommerce versions prior to 5.0.9
**Description**
Improper Verification of Cryptographic Signature occurs due to the `woocommerce api wt stripe` webhook endpoint (`EH Stripe Webhook Handler::handle()`) failing to execute the `StripeWebhook::constructEvent()` function when the `eh stripe webhook secret` option is empty. This condition is common in default installations where the signing secret has not been configured. Consequently, unauthenticated attackers can send forged POST requests that are processed as trusted Stripe events without authentication or authorization. This allows for the manipulation of WooCommerce order statuses through the `payment complete()` function, such as marking unpaid orders as paid, forcing orders into failed states, or fabricating refund and dispute notifications.
**Recommendations**
Update to version 5.0.9 or later.
Configure a valid Stripe webhook signing secret in the plugin settings to ensure signature verification is enforced.