PatchSiren

themehigh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM themehigh CVE published 2026-09-19

CVE-2026-9832

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature. This vulnerability allows unauthenticated attackers to send forged Stripe webhook events, potentially manipulating WooCommerce order statuses. The issue arises when the Stripe webhook signing secret has not been configured by an administrator.

MEDIUM Themehigh CVE published 2026-07-25

CVE-2026-14955

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with subscriber-level access to read arbitrary files. This vulnerability, tracked as CVE-2026-14955, has a CVSS score of 6.5 and is considered a medium priority due to its potential for sensitive information disclosure. The vulnerability exists in all versions up to, [truncated]

MEDIUM ThemeHigh CVE published 2026-05-25

CVE-2026-45217

CVE-2026-45217 is a medium-severity authentication bypass vulnerability in the Stripe Payment Gateway for WooCommerce WordPress plugin, affecting versions up to and including 5.0.7. The vulnerability, classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), enables password recovery exploitation, allowing attackers to potentially bypass authentication controls. The issue was publi [truncated]