PT-2026-95797 · WordPress · Payment Gateway Of Stripe For Woocommerce

·

CVE-2026-9832

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Payment Gateway of Stripe for WooCommerce versions prior to 5.0.9
Description Improper Verification of Cryptographic Signature occurs due to the woocommerce api wt stripe webhook endpoint (EH Stripe Webhook Handler::handle()) failing to execute the StripeWebhook::constructEvent() function when the eh stripe webhook secret option is empty. This condition is common in default installations where the signing secret has not been configured. Consequently, unauthenticated attackers can send forged POST requests that are processed as trusted Stripe events without authentication or authorization. This allows for the manipulation of WooCommerce order statuses through the payment complete() function, such as marking unpaid orders as paid, forcing orders into failed states, or fabricating refund and dispute notifications.
Recommendations Update to version 5.0.9 or later. Configure a valid Stripe webhook signing secret in the plugin settings to ensure signature verification is enforced.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9832

Affected Products

Payment Gateway Of Stripe For Woocommerce