PT-2026-95797 · WordPress · Payment Gateway Of Stripe For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Payment Gateway of Stripe for WooCommerce versions prior to 5.0.9
Description
Improper Verification of Cryptographic Signature occurs due to the
woocommerce api wt stripe webhook endpoint (EH Stripe Webhook Handler::handle()) failing to execute the StripeWebhook::constructEvent() function when the eh stripe webhook secret option is empty. This condition is common in default installations where the signing secret has not been configured. Consequently, unauthenticated attackers can send forged POST requests that are processed as trusted Stripe events without authentication or authorization. This allows for the manipulation of WooCommerce order statuses through the payment complete() function, such as marking unpaid orders as paid, forcing orders into failed states, or fabricating refund and dispute notifications.Recommendations
Update to version 5.0.9 or later.
Configure a valid Stripe webhook signing secret in the plugin settings to ensure signature verification is enforced.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Payment Gateway Of Stripe For Woocommerce