CVE-2026-12654 | paymentplugins Payment Plugins for Stripe WooCommerce Plugin up to 4.0.7 on WordPress Signature Verification payment_complete order_id/gateway_id/status authorization

SecurityVulns

A vulnerability identified as problematic has been detected in paymentplugins Payment Plugins for Stripe WooCommerce Plugin up to 4.0.7 on WordPress. Affected by this issue is the function payment_complete of the component Signature Verification. This manipulation of the argument order_id/gateway_id/status causes authorization bypass.

This vulnerability is tracked as CVE-2026-12654. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More