目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-9832— Stripe for WooCommerce 5.0.8 签名验证漏洞

一分钟漏洞结论

影响对象
themehigh Payment Gateway of Stripe for WooCommerce
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WooCommerce 的 Stripe 支付网关插件(WordPress)存在“加密签名验证不当”漏洞,影响版本包括 5.0.8 及之前所有版本。该漏洞源于公开可访问的 Webhook 端点(由 处理),其中对 的唯一调用被包裹在一个 条件判断中。由于新安装插件后 选项为空,该条件在默认配置下永远不会成立,导致攻击者控制的、未经验证的原始 POST 请求体被直接解码并作为完全可信的 Stripe 事件进行处理,而未经过任何签名验证、身份认证或授权检查。 这使得未认证的攻击者能够发送伪造的 Stripe Webho

CVSS 5.3 · Medium EPSS 0.23% · P14

影响版本矩阵 1

厂商产品 版本范围状态
themehigh Payment Gateway of Stripe for WooCommerce ≤ 5.0.8 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-9832 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint
来源: CVE Program / CVE List V5
Vulnerability Description
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
themehigh Payment Gateway of Stripe for WooCommerce 0 ~ 5.0.8 -

二、漏洞 CVE-2026-9832 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-9832 的情报信息

登录查看更多情报信息。

CVE-2026-9832 厂商安全公告 (1)

CVE-2026-9832 安全博客文章 (1)

CVE-2026-9832 其他参考 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9832

暂无评论


发表评论