STRABL – A checkout solution

STRABL – A checkout solution has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for STRABL – A checkout solution has a vendor fix available, so running the current release closes it.

All of these findings were reported by Teerachai Somprasong. The current release is tested up to WordPress 7.0.3.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all STRABL – A checkout solution vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-3640

STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint

Read the full analysis

Vulnerability Records

1 records
STRABL – A checkout solution banner
Latestv4.8.5

STRABL – A checkout solution

STRABL

Author

STRABL

0.0(0)
0/100
Last Updated
2026-07-20 (26d ago)
Active Installs
0+
Downloads
878
Requires WP
7.0+
Requires PHP
8.0+
Tested up to
WP 7.0.3
Created
2025-12-16 (8mo ago)

STRABL delivers a complete hosted checkout that combines Payment processing, One-click Express Checkout, Apple Pay and Multiple Payment Methods in a single WooCommerce extension. The gateway keeps the native checkout intact while adding configurable purchase buttons, frictionless biometric authentication and automated fulfilment updates. Highlights Customizable checkout with Payment Processing, Express 1-Click Checkout and Zero Pay purchase flows. Built-in support for Apple Pay, Google Pay, Samsung Pay, e-wallets and bank instalments. Access to Recurring Payments (subscriptions), Payment Links & QR Codes Passkey and biometric authentication using device Face ID or fingerprints. Merchant dashboard controls for branding, deferral windows and payment methods. Customer dashboard for managing saved payment details and outstanding Zero Pay balances. Compatibility The plugin is compatible with the classic WooCommerce checkout, WordPress block themes and WooCommerce High-Performance Order Storage (HPOS). External services This plugin communicates with STRABL-operated services to provide the hosted checkout, payment authorisation and merchant configuration workflows. Both sandbox (https://sandbox.api.strabl.com) and production (https://api.strabl.com) environments are available; the same data handling practices apply to each. STRABL API – `https://api.strabl.com` Purpose: retrieves merchant configuration, initiates checkout sessions, stores STRABL customer references and processes webhook updates required to complete orders. Data sent: store identifier, order totals, customer contact details and STRABL customer references are transmitted when a checkout is initiated or webhooks are processed. Terms of Service: https://strabl.io/terms Privacy Policy: https://strabl.io/privacy STRABL Checkout – `https://checkout.strabl.io` Purpose: presents the hosted checkout dialog, collects payment details and performs device-level biometric authentication when enabled. Data sent: the hosted dialog receives checkout tokens generated by the STRABL API along with customer contact details needed to finalise the order. Terms of Service: https://strabl.io/terms Privacy Policy: https://strabl.io/privacy STRABL CDN – `https://cdn.strabl.com` Purpose: delivers static assets (JavaScript, CSS, fonts and images) used by the checkout dialog and Express Checkout button. Data sent: only standard HTTP request metadata (such as IP address and user agent) required to serve static assets is transmitted; no customer payment data is sent to the CDN. Terms of Service: https://strabl.io/terms Privacy Policy: https://strabl.io/privacy Customer data submitted through STRABL is processed under the STRABL privacy policy. The plugin stores a STRABL customer identifier in WooCommerce customer meta to enable returning shopper recognition. Credits Developed and maintained by the STRABL engineering team with contributions from the WordPress community. License This plugin is distributed under the GPLv2 (or later). See http://www.gnu.org/licenses/gpl-2.0.html for the full licence text.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C