Skip to content

Known CVE

Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection

Stripe Payment Plugin for WooCommerce for WordPress versions up to 3.7.9 contains a sql_injection caused by insufficient escaping and lack of preparation on 'id' parameter, letting unauthenticated attackers execute arbitrary SQL queries, exploit requires sending crafted 'id' parameter.

CVE-2024-0705

Critical2024

cve2024 · wp-plugin · wp · wordpress · woocommerce · stripe · sqli · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website