{"id":1088,"date":"2023-06-16T10:48:22","date_gmt":"2023-06-16T10:48:22","guid":{"rendered":"https:\/\/certerassl.com\/blog\/?p=1088"},"modified":"2023-06-16T10:52:48","modified_gmt":"2023-06-16T10:52:48","slug":"a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/","title":{"rendered":"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin, making it possible for an attacker to collect personally identifiable information (PII) from stores using the plugin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Security analysts rated the attack a high grade of 7.5 on a rating scale of 1 to 10, and it does not require authentication.<\/em><\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WooCommerce Stripe Payment Gateway Plugin<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Stripe payment gateway plugin, created by WooCommerce, Automattic, WooThemes, and other developers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It offers a simple way for customers to check out at WooCommerce stores using various credit cards without creating an account.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"331\" src=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/image-1024x331.png\" alt=\"\" class=\"wp-image-1089\" srcset=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/image-1024x331.png 1024w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/image-300x97.png 300w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/image-768x249.png 768w, https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/image.png 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A Stripe account is automatically generated at checkout, providing customers with a seamless e-commerce purchasing experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The plugin uses an application programming interface (API) to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An API acts as an intermediary between two applications, enabling smooth order processing from the WooCommerce shop to Stripe through interaction between the two.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does the WooCommerce Stripe Plugin vulnerability Entail?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability was found by security experts at <strong>Patchstack,<\/strong> who appropriately informed the right parties involved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security professionals at WordPress security companyPatchstack (which discovered the vulnerability) say:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>&#8220;This plugin has an IDOR vulnerability, which stands for Unauthenticated Insecure Direct Object Reference.<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Due to a vulnerability, any user without authentication can view the email, username, and complete address of any WooCommerce order. The described vulnerability was fixed in version 7.4.1 with some backported fixed versions and assigned CVE-2023-34000.<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>The issues allow an attacker to read order information in the site&#8217;s page source or on the front end due to the lacking of order ownership checks.&#8221;<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The &#8216;<strong>javascript_params<\/strong>&#8216; and &#8216;<strong>payment_fields<\/strong>&#8216; routines lack sufficient access control and handle data unsafely, resulting in a security flaw.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended: <strong><a href=\"https:\/\/patchstack.com\/articles\/unauthenticated-idor-to-pii-disclosure-vulnerability-in-woocommerce-stripe-gateway-plugin\">Unauthenticated IDOR to PII Disclosure in WooCommerce Stripe Gateway Plugin<\/a><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More than 900,000 active installations of the plugin exist, and based on the version use statistics that are currently accessible, hundreds of thousands of them could potentially be attacked.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Impact of the WooCommerce Stripe Plugin Versions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Versions 7.4.0 and earlier are affected by the vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The developers upgraded the plugin to version 7.4.1, the most secure version.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>According to the official plugin changelog, the following updates to security were made:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>&#8220;Fix \u2013 Add Order Key Validation.<\/em><\/strong><em><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Fix \u2013 Add sanitization and escaping some outputs.&#8221;<\/em><\/strong><em><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are specific issues that are required to be resolved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first is a lack of validation, often a check to identify whether a request comes from a legitimate source.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second one is sanitization, which describes a method of preventing any invalid input. For instance, if a field accepts just text, it should be configured so scripts cannot be uploaded.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patchstack&#8217;s security advisory provided more technical information regarding the root causes of the vulnerabilities that this version addresses. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Store owners are strongly advised to upgrade to version 7.4.1.<\/em><\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"recent-vulnerabilities-and-attacks-of-2023\">Recent Vulnerabilities of 2023<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/certera.com\/blog\/balada-malware-infects-million-wordpress-websites\">Balada Malware Attack on WordPress<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/elementor-pro-vulnerability-hackers-exploited-bug\">WordPress Plugin Elementor Pro Found Vulnerable<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/wordpress-code-snippets-plugin-vulnerability-1-million-sites-compromised\">WordPress Code Snippets Plugin Vulnerability<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certera.com\/blog\/atomic-wallet-security-glitch-35m-cryptocurrency-theft\">Atomic Wallet Security Glitch<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin, making it possible for an attacker to collect personally identifiable information (PII) from stores using the plugin. Security analysts rated the attack a high grade of 7.5 on a rating scale of 1 to 10, and it does not require authentication. WooCommerce Stripe<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":1090,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32,19],"tags":[74,73,77,75,76],"class_list":["post-1088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerability","category-website-security","tag-patch-in-woocommerce-stripe-gateway","tag-security-vulnerability-in-woocommerce-stripe-gateway","tag-woocommerce-stripe-payment-gateway-plugin-vulnerabilities","tag-wordpress-woocommerce-stripe-payment-gateway-plugin","tag-wordpress-woocommerce-stripe-payment-gateway-plugin-vulnerability","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>A Security Vulnerability in WordPress WooCommerce Stripe Gateway Plugin<\/title>\n<meta name=\"description\" content=\"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites\" \/>\n<meta property=\"og:description\" content=\"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-16T10:48:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-16T10:52:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites\",\"datePublished\":\"2023-06-16T10:48:22+00:00\",\"dateModified\":\"2023-06-16T10:52:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/\"},\"wordCount\":484,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\",\"keywords\":[\"patch in WooCommerce Stripe Gateway\",\"security vulnerability in WooCommerce Stripe Gateway\",\"WooCommerce Stripe Payment Gateway Plugin Vulnerabilities\",\"WordPress WooCommerce Stripe Payment Gateway Plugin\",\"WordPress WooCommerce Stripe Payment Gateway Plugin Vulnerability\"],\"articleSection\":[\"Vulnerability\",\"Website Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#respond\"]}],\"copyrightYear\":\"2023\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/\",\"name\":\"A Security Vulnerability in WordPress WooCommerce Stripe Gateway Plugin\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\",\"datePublished\":\"2023-06-16T10:48:22+00:00\",\"dateModified\":\"2023-06-16T10:52:48+00:00\",\"description\":\"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp\",\"width\":960,\"height\":620,\"caption\":\"Security Vulnerability in WooCommerce Stripe Payment Gateway Plugin\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"A Security Vulnerability in WordPress WooCommerce Stripe Gateway Plugin","description":"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/","og_locale":"en_US","og_type":"article","og_title":"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites","og_description":"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.","og_url":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2023-06-16T10:48:22+00:00","article_modified_time":"2023-06-16T10:52:48+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_image":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites","datePublished":"2023-06-16T10:48:22+00:00","dateModified":"2023-06-16T10:52:48+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/"},"wordCount":484,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","keywords":["patch in WooCommerce Stripe Gateway","security vulnerability in WooCommerce Stripe Gateway","WooCommerce Stripe Payment Gateway Plugin Vulnerabilities","WordPress WooCommerce Stripe Payment Gateway Plugin","WordPress WooCommerce Stripe Payment Gateway Plugin Vulnerability"],"articleSection":["Vulnerability","Website Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#respond"]}],"copyrightYear":"2023","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/","url":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/","name":"A Security Vulnerability in WordPress WooCommerce Stripe Gateway Plugin","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","datePublished":"2023-06-16T10:48:22+00:00","dateModified":"2023-06-16T10:52:48+00:00","description":"A security vulnerability was discovered in the WooCommerce Stripe payment gateway plugin by security expert Patchstack. Know everything about this patch.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/06\/vulnerability-in-woocommerce-stripe-payment-gateway-plugin-jpg.webp","width":960,"height":620,"caption":"Security Vulnerability in WooCommerce Stripe Payment Gateway Plugin"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/a-security-vulnerability-in-woocommerce-stripe-gateway-affects-over-900k-websites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"A Security Vulnerability in WooCommerce Stripe Gateway Affects Over 900K Websites"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/1088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=1088"}],"version-history":[{"count":2,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/1088\/revisions"}],"predecessor-version":[{"id":1093,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/1088\/revisions\/1093"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/1090"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=1088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=1088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=1088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}