The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature. This vulnerability allows unauthenticated attackers to send forged Stripe webhook events, potentially manipulating WooCommerce order statuses. The issue arises when the Stripe webhook signing secret has not been configured by an administrator.
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with subscriber-level access to read arbitrary files. This vulnerability, tracked as CVE-2026-14955, has a CVSS score of 6.5 and is considered a medium priority due to its potential for sensitive information disclosure. The vulnerability exists in all versions up to, [truncated]
CVE-2026-45217 is a medium-severity authentication bypass vulnerability in the Stripe Payment Gateway for WooCommerce WordPress plugin, affecting versions up to and including 5.0.7. The vulnerability, classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), enables password recovery exploitation, allowing attackers to potentially bypass authentication controls. The issue was publi [truncated]