/Vulnerability Library

Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection

CVE-2024-0705
Verified

Description

Stripe Payment Plugin for WooCommerce for WordPress versions up to 3.7.9 contains a sql_injection caused by insufficient escaping and lack of preparation on 'id' parameter, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'id' parameter.

Severity

Critical

Published Date

February 6, 2026

Template Author

shivam kamboj

CVE-2024-0705.yaml
9.5Severity

CVSS Metrics

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0705https://www.wordfence.com/threat-intel/vulnerabilities/id/2652a7fc-b610-40f1-8b76-2129f59390ec?source=cve

Remediation Steps

Update to the latest version of the plugin, above 3.7.9, to fix the vulnerability.