Top WordPress ecommerce plugin has a major security flaw, so patch now
WordPress users who have installed the WooCommerce Stripe Gateway Plugin are being urged to update to at least version 7.4.1 following the news of a major vulnerability potentially exposing users’ PII data.
The vulnerability, assigned CVE-2023-34000, relates to the free version of the WooCommerce Stripe Gateway plugin, specifically versions 7.4.0 and below. The popular ecommerce plugin has amassed more than 900,000 active installations, making the severity of the bug particularly alarming.
Because the plugin allows customers to process payments on their chosen business’s own WordPress page, rather than being diverted to an externally hosted page, the Stripe plugin has proven particularly popular.
Update Stripe WordPress plugin now
The cause for concern for CVE-2023-34000 is that any unauthenticated user has been able to access the PII data from any WooCommerce order, including email addresses, names, and full addresses.
Credited with first finding the vulnerability, WordPress security service provider Patchstack notified the plugin vendor way back on April 17, but it wasn’t until just over six weeks later that version 7.4.1 was released to patch the issue.
The changelog for version 7.4.1 includes two entries: “Add Order Key Validation,” and “Add sanitization and escaping some outputs.”
Despite the security scare, the payment plugin remains a staple for many ecommerce businesses who choose WordPress, for its ability to process Visa, MasterCard, and American Express payments – including via Apple Pay – via Stripe’s API.
WooCommerce did not immediately respond to TechRadar Pro’s request for comment on the vulnerability which took several weeks to fix.
WordPress users who have installed the WooCommerce Stripe Gateway Plugin are being urged to update to at least version 7.4.1 following the news of a major vulnerability potentially exposing users’ PII data. The vulnerability, assigned CVE-2023-34000, relates to the free version of the WooCommerce Stripe Gateway plugin, specifically versions 7.4.0…
Recent Posts
- This chunky little tablet got my kid to clean up his toys
- OpenAI will let the US government review its AI models before release
- Seagate FireCuda X Vault review: Large capacity and decent transfer rates make this external hard drive a great solution for video and photography
- I customized a MacBook Neo with colorful spare parts
- EveryPlate Meal Kit Review (2026): Low Cost, Simplicity, Flavor
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023