Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
CVE-2024-0705
Verified
Description
Stripe Payment Plugin for WooCommerce for WordPress versions up to 3.7.9 contains a sql_injection caused by insufficient escaping and lack of preparation on 'id' parameter, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'id' parameter.
Severity
Critical
Published Date
February 6, 2026
Template Author
shivam kamboj
CVE-2024-0705.yaml
Remediation Steps
Update to the latest version of the plugin, above 3.7.9, to fix the vulnerability.