CVE

CVE-2026-12654 — Payment Plugins for Stripe WooCommerce < 4.0.8 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12654 Payment Plugins for Stripe WooCommerce < 4.0.8 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret Unknown < 4.0.8 4.0.8

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.