WP Stripe Checkout

WP Stripe Checkout has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Storage Of Sensitive Data In A Mechanism Without Access Control.

Every one of the 3 issues recorded for WP Stripe Checkout has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. WP Stripe Checkout is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all WP Stripe Checkout vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2023-52143

WP Stripe Checkout <= 1.2.2.37 - Sensitive Information Exposure via Debug Log

Read the full analysis

Vulnerability Records

3 records
WP Stripe Checkout banner
Latestv1.2.2.60

WP Stripe Checkout

Noor Alam

Author

Noor Alam

4.4(23)
88/100
Last Updated
2026-09-01 (12d ago)
Active Installs
1,000+
Downloads
198,865
Requires WP
5.3+
Requires PHP
0+
Tested up to
WP 7.1
Created
2016-11-02 (10y ago)

Stripe Checkout plugin lets you accept credit card payments via Stripe on your WordPress site. Whether you are selling products, offering services, or collecting donations, our lightweight Stripe payment plugin is built for speed, security, and simplicity. Accept Stripe payments on your WordPress website in minutes WP Stripe Checkout is great for: Freelancers accepting client payments Nonprofits collecting donations Selling goods or services Subscription-based offerings WP Stripe Checkout Add-ons Variable Price Variable Quantity Submit Type Terms of Service Payment Link Email Variable Currency WP User Tracking WP User Only Button Product SEO Stripe Checkout Payment Methods Apple Pay Google Pay Alipay WeChat Pay Bancontact EPS giropay iDEAL Przelewy24 Sofort Afterpay/Clearpay Boleto OXXO ACH Direct Debit Bacs Direct Debit BECS Debit Canadian pre-authorised debit (PAD) SEPA Direct Debit Features Accept credit/debit card payments with Stripe Easy setup with Stripe API keys Secure, PCI-compliant payment processing Customizable payment button via shortcode Supports one-time and recurring payments via Stripe payment links Mobile-friendly Stripe Checkout integration Detailed transaction logs in your dashboard Support Dynamic 3D Secure payment authentication. Support payment processing with Stripe test cards. Support phone number collection at checkout. Support user redeemable promotion codes at checkout. Localized for different languages. Automatically email Stripe receipts to your customers. No complex setup like a membership/e-commerce plugin. Easily Switch between live and sandbox mode for testing. Send a purchase confirmation email to your customer after a transaction. Send a sale notification email to a chosen recipient (e.g. the seller) after a transaction. Automatic VAT/tax ID collection at checkout Support orders of free trial payments without payment methods Support Product Schema markup through Product SEO add-on (It can help search engines and AI crawlers discover products) WP Stripe Checkout Configuration Once you have activated the plugin, you need to add your Stripe account API keys. It’s located under “WP Stripe Checkout -> Settings -> General”. WP Stripe Checkout Emails Stripe checkout plugin comes with an “Emails” tab where you will be able to configure some email related settings. Stripe Webhook Endpoint Go to “Developers > Webhooks > Add endpoint” and insert the URL shown in the plugin settings. Select this event – “checkout.session.completed” and click “Add endpoint”. This is where Stripe will send a notification after a checkout payment is successful. You will also need to add the “checkout.session.async_payment_succeeded” and “checkout.session.async_payment_failed” events if you plan to use a payment method where there can be a delay in payment confirmation. For example: Bacs Direct Debit Boleto Canadian pre-authorised debits OXXO SEPA Direct Debit SOFORT ACH Direct Debit How to use Stripe Checkout The easiest way to start accepting Stripe payments is to create a product and add the following shortcode to a post/page: [wp_stripe_checkout id="1"] Replace 1 with the actual product ID. How to use Stripe Payment Links This method allows you to integrate Stripe payment links with the plugin. Step 1: Create a Payment Link Log in to your Stripe account dashboard and navigate to the “Payment links” page (Payments > Payment links). Select an existing product or add a new one to create a payment link. Step 2: Use the Payment Link in a Shortcode In order to create a button with the payment link you can add the following shortcode to a post/page: [wp_stripe_checkout_payment_link url="https://buy.stripe.com/live_6gPE4jw7dMbUKdd3345"] For detailed setup instructions please visit the WP Stripe Checkout plugin page.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C