Extension WordPress

Vulnérabilités WooCommerce Stripe Payment Gateway

Cette page rassemble les failles publiées pour WooCommerce Stripe Payment Gateway, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WooCommerce Stripe Payment Gateway

5 fiches

CVE-2026-2381 Moyenne · 6,5
WooCommerce Stripe Payment Gateway

WooCommerce Stripe Payment Gateway <= 10.7.0 – Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a…

Versions affectées

*-10.7.0

Correctif

10.8.0

Publication

15/06/2026

CVE-2023-51502 Moyenne · 6,5
WooCommerce Stripe Payment Gateway

WooCommerce Stripe Payment Gateway <= 7.6.1 – Insecure Direct Object Reference via update_payment_intent_ajax

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.6.1 via the update_payment_intent_ajax due to missing validation on a user controlled key. This makes it…

Versions affectées

*-7.6.1

Correctif

7.6.2

Publication

27/12/2023

CVE-2023-34000 Élevée · 7,5
WooCommerce Stripe Payment Gateway

WooCommerce Stripe Payment Gateway <= 7.4.0 – Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 7.4.0. This is due to insufficient validation in the payment_fields() and javascript_params () functions that do not…

Versions affectées

[5.5.0, 5.5.1), [5.6.0, 5.6.3), [5.7.0, 5.7.1), [5.8.0, 5.8.2), [5.9.0, 5.9.1), [6.0.0, 6.0.1), [6.1.0, 6.1.1), [6.2.0, 6.2.1), [6.3.0, 6.3.1), [6.4.0, 6.4.4), [6.5.0, 6.5.2), [6.6.0, 6.6.1), [6.7.0, 6.7.1), [6.8.0, 6.8.1), [6.9.0, 6.9.1), [7.0.0, 7.0.3), [7.1.0, 7.1.1), [7.2.0, 7.2.1), [7.3.0, 7.3.1), *-5.5.0, 7.4.0

Correctif

5.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1

Publication

13/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités