WordPress Plugin Vulnerabilities

Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-pay

Description

The plugin does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers.

Proof of Concept

Affects Plugins

Fixed in 4.0.12

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
m1w34p0n
Submitter
m1w34p0n
Verified
Yes

Timeline

Publicly Published
2026-09-07 (about 2 days ago)
Added
2026-09-07 (about 1 day ago)
Last Updated
2026-09-07 (about 1 day ago)

Other