Known vulnerabilities in WooCommerce Stripe Payment Gateway
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
5Reported vulnerabilities
7.5Highest CVSS score
10.8.5Latest version
700,000+Active installs
What to do now
Update WooCommerce Stripe Payment Gateway to 10.8.0 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2023-34000 | High | 1.2% | 5.5.0 and earlier 5.5.0 up to (but not including) 5.5.1 5.6.0 up to (but not including) 5.6.3 5.7.0 up to (but not including) 5.7.1 5.8.0 up to (but not including) 5.8.2 5.9.0 up to (but not including) 5.9.1 6.0.0 up to (but not including) 6.0.1 6.1.0 up to (but not including) 6.1.1 6.2.0 up to (but not including) 6.2.1 6.3.0 up to (but not including) 6.3.1 6.4.0 up to (but not including) 6.4.4 6.5.0 up to (but not including) 6.5.2 6.6.0 up to (but not including) 6.6.1 6.7.0 up to (but not including) 6.7.1 6.8.0 up to (but not including) 6.8.1 6.9.0 up to (but not including) 6.9.1 7.0.0 up to (but not including) 7.0.3 7.1.0 up to (but not including) 7.1.1 7.2.0 up to (but not including) 7.2.1 7.3.0 up to (but not including) 7.3.1 7.4.0 to 7.4.0 (inclusive) |
5.5.1 |
June 13, 2023 |
| CVE-2023-51502 | Medium | 0.6% | 7.6.1 and earlier | 7.6.2 |
December 27, 2023 |
| CVE-2026-2381 | Medium | 0.4% | 0 to 10.7.0 (inclusive) | 10.8.0 |
June 16, 2026 |
| CVE-2023-35049 | Medium | 0.6% | 7.4.0 and earlier | 7.4.1 |
June 13, 2023 |
| CVE-2023-44999 | Medium | 0.2% | Before 7.6.1 | 7.6.1 |
October 17, 2023 |