Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

WooCommerce Stripe Payment Gateway Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 5 vulnerability records associated with WooCommerce Stripe Payment Gateway, published between 2023 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

5Total records
0Critical
1High
4Medium
0Low
0Informational
5Patched records
0Currently marked unpatched
2023-06-13First disclosure
2026-06-15Latest disclosure
5 of 5CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202344 records
202611 records

Severity Breakdown

SeverityRecordsShare
High120%
Medium480%

Vulnerability-Type Breakdown

Missing Authorization

4 records80%

First: 2023. Latest: 2026.

CSRF

1 record20%

First: 2023. Latest: 2023.

Patch Status

Patched
5
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 10.8.0
  • 7.6.2
  • 7.6.1
  • 7.3.1
  • 7.2.1
  • 7.1.1
  • 7.0.3
  • 6.9.1
  • 6.8.1
  • 6.7.1
  • 6.6.1
  • 6.5.2
  • 6.4.4
  • 6.3.1
  • 6.2.1
  • 6.1.1
  • 6.0.1
  • 5.9.1
  • 5.8.2
  • 5.7.1
  • 5.6.3
  • 5.5.1
  • 7.4.1

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-10.7.0WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' ParameterJune 15, 202610.8.0Medium
*-7.6.1WooCommerce Stripe Payment Gateway <= 7.6.1 - Insecure Direct Object Reference via update_payment_intent_ajaxDecember 27, 20237.6.2Medium
[*, 7.6.1)Stripe Gateway <= 7.6.0 - Cross-Site Request ForgeryOctober 17, 20237.6.1Medium
7.4.0WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[7.3.0, 7.3.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[7.2.0, 7.2.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[7.1.0, 7.1.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[7.0.0, 7.0.3)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.9.0, 6.9.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.8.0, 6.8.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.7.0, 6.7.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.6.0, 6.6.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.5.0, 6.5.2)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.4.0, 6.4.4)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.3.0, 6.3.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.2.0, 6.2.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.1.0, 6.1.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[6.0.0, 6.0.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[5.9.0, 5.9.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[5.8.0, 5.8.2)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[5.7.0, 5.7.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[5.6.0, 5.6.3)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
[5.5.0, 5.5.1)WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
*-5.5.0WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information DisclosureJune 13, 20235.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1High
*-7.4.0WooCommerce Stripe Payment Gateway <= 7.4.0 - Missing AuthorizationJune 13, 20237.4.1Medium

Selected source records

Latest Records

MediumCVE-2026-2381

WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

Published: June 15, 2026

Affected versions
*-10.7.0
Patched versions
10.8.0
Original Wordfence record
MediumCVE-2023-51502

WooCommerce Stripe Payment Gateway <= 7.6.1 - Insecure Direct Object Reference via update_payment_intent_ajax

Published: December 27, 2023

Affected versions
*-7.6.1
Patched versions
7.6.2
Original Wordfence record
MediumCVE-2023-44999

Stripe Gateway <= 7.6.0 - Cross-Site Request Forgery

Published: October 17, 2023

Affected versions
[*, 7.6.1)
Patched versions
7.6.1
Original Wordfence record
MediumCVE-2023-35049

WooCommerce Stripe Payment Gateway <= 7.4.0 - Missing Authorization

Published: June 13, 2023

Affected versions
*-7.4.0
Patched versions
7.4.1
Original Wordfence record
HighCVE-2023-34000

WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure

Published: June 13, 2023

Affected versions
*-5.5.0; [5.5.0, 5.5.1); [5.6.0, 5.6.3); [5.7.0, 5.7.1); [5.8.0, 5.8.2); [5.9.0, 5.9.1); [6.0.0, 6.0.1); [6.1.0, 6.1.1); [6.2.0, 6.2.1); [6.3.0, 6.3.1); [6.4.0, 6.4.4); [6.5.0, 6.5.2); [6.6.0, 6.6.1); [6.7.0, 6.7.1); [6.8.0, 6.8.1); [6.9.0, 6.9.1); [7.0.0, 7.0.3); [7.1.0, 7.1.1); [7.2.0, 7.2.1); [7.3.0, 7.3.1); 7.4.0
Patched versions
5.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1
Original Wordfence record

Highest-Severity Records

HighCVE-2023-34000

WooCommerce Stripe Payment Gateway <= 7.4.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure

Published: June 13, 2023

Affected versions
*-5.5.0; [5.5.0, 5.5.1); [5.6.0, 5.6.3); [5.7.0, 5.7.1); [5.8.0, 5.8.2); [5.9.0, 5.9.1); [6.0.0, 6.0.1); [6.1.0, 6.1.1); [6.2.0, 6.2.1); [6.3.0, 6.3.1); [6.4.0, 6.4.4); [6.5.0, 6.5.2); [6.6.0, 6.6.1); [6.7.0, 6.7.1); [6.8.0, 6.8.1); [6.9.0, 6.9.1); [7.0.0, 7.0.3); [7.1.0, 7.1.1); [7.2.0, 7.2.1); [7.3.0, 7.3.1); 7.4.0
Patched versions
5.5.1, 5.6.3, 5.7.1, 5.8.2, 5.9.1, 6.0.1, 6.1.1, 6.2.1, 6.3.1, 6.4.4, 6.5.2, 6.6.1, 6.7.1, 6.8.1, 6.9.1, 7.0.3, 7.1.1, 7.2.1, 7.3.1, 7.4.1
Original Wordfence record
MediumCVE-2023-51502

WooCommerce Stripe Payment Gateway <= 7.6.1 - Insecure Direct Object Reference via update_payment_intent_ajax

Published: December 27, 2023

Affected versions
*-7.6.1
Patched versions
7.6.2
Original Wordfence record
MediumCVE-2026-2381

WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter

Published: June 15, 2026

Affected versions
*-10.7.0
Patched versions
10.8.0
Original Wordfence record
MediumCVE-2023-35049

WooCommerce Stripe Payment Gateway <= 7.4.0 - Missing Authorization

Published: June 13, 2023

Affected versions
*-7.4.0
Patched versions
7.4.1
Original Wordfence record
MediumCVE-2023-44999

Stripe Gateway <= 7.6.0 - Cross-Site Request Forgery

Published: October 17, 2023

Affected versions
[*, 7.6.1)
Patched versions
7.6.1
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory