CVE · Medium

CVE-2026-2381 — WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 10.8.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2381 WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 10.8.0 Missing Authorization Medium 6.5 < 10.8.0 10.8.0 2026-06-15

CVE-2026-2381

The WooCommerce Stripe Payment Gateway plugin for WordPress contains a vulnerability that allows unauthorized modification of order data. Specifically, the plugin's `ajax_pay_for_order()` function does not properly verify the requesting user's ownership of the target order, allowing an attacker to manipulate an order's status by providing a fake payment method. This can be exploited to force a pending order into a failed status by sequentially enumerating order IDs, resulting in a payment exception that updates the order status.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.