Security update for Stripe for WooCommerce

We have released a security update for Stripe for WooCommerce. If you run, maintain, host, or support WooCommerce stores with the extension installed, update each affected store to version 10.8.5 or the patched build for its current release line immediately.

The update addresses security issues identified through Automattic’s proactive internal testing. We have no evidence that these issues have been exploited, and we have no evidence that store, customer, or payment data was accessed. The most significant issue could, under certain circumstances, cause an affected store to become unavailable.

Versions 9.7.0 through 10.8.4 are affected. Patched builds are available for each release line from 9.7.x through 10.8.x.

This is a separate update from the Stripe for WooCommerce payment validation patch published on July 14. Stores that previously updated to 10.6.2, 10.7.1, or 10.8.4 for that advisory must update again.

Update Stripe for WooCommerce immediately

Check the installed version on every store you manage, including stores that receive automatic plugin updates.

From the WordPress Admin dashboard:

  1. Go to Plugins > Installed Plugins.
  2. Look for WooCommerce Stripe Payment Gateway or Stripe for WooCommerce.
  3. If an update is available, click Update now. If you don’t see the plugin listed, you don’t need to update.
  4. Confirm that the store is running 10.8.5 or one of the patched branch versions listed below.
  5. Test checkout after the update and confirm that Stripe payment methods are available.

We are coordinating automatic updates with the WordPress.org Plugins Team where possible. Stores hosted on Automattic infrastructure or configured for automatic plugin updates may already have received a patch. Developers, agencies, and hosts should still verify the installed version directly.

Patched builds are available for affected release lines

We recommend updating to 10.8.5, the latest patched release. If a store must remain on its current release line temporarily, update it to the corresponding patched build.

Release linePatched version
10.8.x10.8.5
10.7.x10.7.2
10.6.x10.6.3
10.5.x10.5.4
10.4.x10.4.1
10.3.x10.3.2
10.2.x10.2.1
10.1.x10.1.1
10.0.x10.0.2
9.9.x9.9.3
9.8.x9.8.2
9.7.x9.7.2

Versions earlier than 9.7.0 are not affected by this specific issue. They are also older releases, so we recommend moving to the latest supported version of Stripe for WooCommerce.

The most significant issue could, under certain conditions, cause an affected store to become unavailable. It does not provide access to customer or payment data.

The release also addresses related security findings in recent versions of the extension. We are not publishing procedural details while stores are still updating because that information could make unpatched sites easier to target. We will update this advisory with more technical detail when it is safe to do so.

We found the issues through proactive security testing

Automattic identified these issues during internal security testing and began preparing fixes and backports across the affected release lines. Monitoring has found no evidence of real-world exploitation.

The coordinated release and automatic-update process is intended to reduce the time that affected stores remain on a vulnerable version. Because WooCommerce stores can be self-hosted and managed in many different ways, developers and service providers should verify updates rather than relying on the rollout alone.

WooCommerce support can help with update questions

If you manage a store and need help updating Stripe for WooCommerce, contact WooCommerce support.

If you maintain an extension, host WooCommerce stores, or support merchants and have a developer-specific question, join the WooCommerce Community Slack.

We will update this post if more information becomes available.


Leave a Reply

Your email address will not be published. Required fields are marked *