What is CVE-2026-12654?
This vulnerability affects the Payment Plugins for Stripe WooCommerce plugin for WordPress. Due to an authorization bypass in versions up to and including 4.0.7, unauthenticated attackers can perform certain unauthorized actions.
Azərbaycanca: Bu boşluq WordPress üçün Payment Plugins for Stripe WooCommerce plagininə aiddir. 4.0.7 və daha əvvəlki versiyalarda mövcud olan authorization bypass zəifliyi səbəbindən, autentifikasiya olunmamış hücumçular müəyyən əməliyyatlar icra edə bilərlər.
Related CVEs
link basis: same weakness class CWE-862; shared vendors: Stripe, WooCommerce
FAQ2
Which plugin is affected by CVE-2026-12654?
This vulnerability affects the Payment Plugins for Stripe WooCommerce plugin for WordPress.
Does an attacker need to be authenticated to exploit CVE-2026-12654?
No, due to this authorization bypass vulnerability, unauthenticated attackers can perform certain unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.