WordPress security by component
Stripe Payment Gateway for WooCommerce
Plugin description
Stripe Payment Gateway for WooCommerce is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 25, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
payment-gateway-stripe-and-woocommerce-integrationLatest vulnerability
CVE-2026-45217: Stripe Payment Gateway for WooCommerce: Privilege escalation or authentication bypass
Stripe Payment Gateway for WooCommerce is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.0.7.
| Safe version |
|
||
|---|---|---|---|
| May 25, 2026 |
CVE-2026-45217
Stripe Payment Gateway for WooCommerce: Privilege escalation or authentication bypass
Stripe Payment Gateway for WooCommerce is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.0.7.
|
5.0.8 |
CVE6.5
NVDPending
|
| Aug 31, 2023 |
CVE-2023-3162
Stripe Payment Plugin for WooCommerce: Privilege escalation or authentication bypass
Stripe Payment Plugin for WooCommerce is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|