CVE-2026-12654
Received Received - Intake

Authorization Bypass in Payment Plugins for Stripe WooCommerce

Vulnerability report for CVE-2026-12654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Wordfence

Description

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending asynchronous WooCommerce orders as paid by forging a charge.pending event with attacker-controlled metadata.order_id, metadata.gateway_id, and a charge object carrying status=succeeded and captured=true, triggering payment_complete() and downstream fulfillment flows with an attacker-supplied transaction ID. Exploitation requires the merchant to have left the webhook_secret_test or webhook_secret_live option blank, which is the plugin's default state until a Stripe-issued whsec_ value is manually configured; once a non-empty secret is set, the signature verification cannot be bypassed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
payment_plugins stripe_woocommerce to 4.0.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the Payment Plugins for Stripe WooCommerce plugin for WordPress. It allows unauthenticated attackers to mark arbitrary pending WooCommerce orders as paid by forging a charge.pending event with attacker-controlled details. This triggers payment completion and downstream fulfillment flows with a fake transaction ID.

Detection Guidance

Check WordPress plugin logs for unauthorized order status changes or forged webhook events. Look for pending orders marked as paid without valid transactions. Inspect webhook_secret_test or webhook_secret_live settings in the plugin configuration.

Impact Analysis

Attackers could exploit this to trick systems into processing fake payments, leading to financial losses or unauthorized order fulfillments. Merchants using the plugin without configuring a Stripe webhook secret are at risk.

Mitigation Strategies
  • Set a non-empty webhook_secret_test and webhook_secret_live value in the plugin settings to enable signature verification.
  • Update the Payment Plugins for Stripe WooCommerce plugin to the latest version if available.
  • Review all pending orders for unauthorized changes and verify transaction IDs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart