Extension WordPress
Vulnérabilités WooCommerce Stripe Payment Gateway
Cette page rassemble les failles publiées pour WooCommerce Stripe Payment Gateway, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WooCommerce Stripe Payment Gateway
5 fiches
WooCommerce Stripe Payment Gateway <= 10.7.0 – Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a…
*-10.7.0
10.8.0
15/06/2026
WooCommerce Stripe Payment Gateway <= 7.6.1 – Insecure Direct Object Reference via update_payment_intent_ajax
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.6.1 via the update_payment_intent_ajax due to missing validation on a user controlled key. This makes it…
*-7.6.1
7.6.2
27/12/2023
Stripe Gateway <= 7.6.0 – Cross-Site Request Forgery
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 7.6.1 (exclusive). This is due to missing or incorrect nonce validation on the maybe_handle_redirect function. This makes it possible…
[*, 7.6.1)
7.6.1
17/10/2023
WooCommerce Stripe Payment Gateway <= 7.4.0 – Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 7.4.0. This is due to insufficient validation in the payment_fields() and javascript_params () functions that do not…
[5.5.0, 5.5.1), [5.6.0, 5.6.3), [5.7.0, 5.7.1), [5.8.0, 5.8.2), [5.9.0, 5.9.1), [6.0.0, 6.0.1), [6.1.0, 6.1.1), [6.2.0, 6.2.1), [6.3.0, 6.3.1), [6.4.0, 6.4.4), [6.5.0, 6.5.2), [6.6.0, 6.6.1), [6.7.0, 6.7.1), [6.8.0, 6.8.1), [6.9.0, 6.9.1), [7.0.0, 7.0.3), [7.1.0, 7.1.1), [7.2.0, 7.2.1), [7.3.0, 7.3.1), *-5.5.0, 7.4.0
5.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1
13/06/2023
WooCommerce Stripe Payment Gateway <= 7.4.0 – Missing Authorization
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.4.0. This makes it possible for unauthenticated attackers to perform…
*-7.4.0
7.4.1
13/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.