Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9832— Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint

Quick assessment

Affected
themehigh Payment Gateway of Stripe for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WooCommerce 的 Stripe 支付网关插件(WordPress)存在“加密签名验证不当”漏洞,影响版本包括 5.0.8 及之前所有版本。该漏洞源于公开可访问的 Webhook 端点(由 处理),其中对 的唯一调用被包裹在一个 条件判断中。由于新安装插件后 选项为空,该条件在默认配置下永远不会成立,导致攻击者控制的、未经验证的原始 POST 请求体被直接解码并作为完全可信的 Stripe 事件进行处理,而未经过任何签名验证、身份认证或授权检查。 这使得未认证的攻击者能够发送伪造的 Stripe Webho

CVSS 5.3 · Medium EPSS 0.23% · P14

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
themehigh Payment Gateway of Stripe for WooCommerce ≤ 5.0.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9832

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only call to `\Stripe\Webhook::constructEvent()` inside an `if (!empty($endpoint_secret))` guard that is never entered on default installations — because the `eh_stripe_webhook_secret` option is empty after a fresh plugin install — causing the raw, attacker-controlled POST body to be decoded and processed as a fully trusted Stripe event without any signature verification, authentication, or authorization. This makes it possible for unauthenticated attackers to send forged Stripe webhook events to manipulate WooCommerce order statuses, including marking unpaid orders as paid or completed via `payment_complete()`, forcing legitimate orders into a failed state, fabricating dispute notifications, and injecting forged refund events. This vulnerability is only exploitable when the Stripe webhook signing secret has not been configured by an administrator; once a valid signing secret is saved, `\Stripe\Webhook::constructEvent()` is enforced and forged requests are rejected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themehigh Payment Gateway of Stripe for WooCommerce 0 ~ 5.0.8 -

II. Public POCs for CVE-2026-9832

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9832

登录查看更多情报信息。

Vendor Advisories for CVE-2026-9832 (1)

Security Blog Posts for CVE-2026-9832 (1)

Other References for CVE-2026-9832 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9832

No comments yet


Leave a comment