Stripe for WooCommerce security update: check your version and test checkout

WooCommerce has released a security update for Stripe for WooCommerce, and this one is worth checking immediately if your store uses Stripe payments. Affected stores should update to version 10.8.5, or to the patched build for their current release line, then test checkout. In plain store-owner terms: this is not the update to leave for Friday evening.

Key Takeaways

  • Affected versions are Stripe for WooCommerce 9.7.0 through 10.8.4.
  • WooCommerce recommends updating to Stripe for WooCommerce 10.8.5 where possible.
  • Stores updated for the July 14 advisory may still need another update.
  • The main reported risk is store unavailability under certain conditions, not confirmed data exposure.
  • After updating, test checkout and confirm Stripe payment methods are available.

Which Stripe for WooCommerce versions are affected

The advisory says versions 9.7.0 through 10.8.4 are affected. WooCommerce recommends moving to 10.8.5, the latest patched release. Patched builds are also available for older release lines from 9.7.x through 10.8.x, in case a store cannot move to the newest version immediately.

Versions earlier than 9.7.0 are not affected by this specific issue, according to WooCommerce, but they are still older releases. That is not exactly a comforting long-term maintenance plan.

Why the July update is not enough

This update is separate from the Stripe for WooCommerce payment validation patch published on July 14. That detail matters because some stores may look recently patched but still be exposed to this new advisory.

WooCommerce specifically says stores previously updated to 10.6.2, 10.7.1, or 10.8.4 for the July advisory must update again. So do not assume that a recent Stripe plugin update means the job is done.

What store owners should check now

WooCommerce says to check every store you manage, including stores with automatic plugin updates enabled. In WordPress Admin, go to Plugins > Installed Plugins, then look for WooCommerce Stripe Payment Gateway or Stripe for WooCommerce. If an update is available, apply it.

After that, confirm the store is running 10.8.5 or the correct patched version for its release line. Automatic updates are helpful, but for payment plugins, verification beats hope.

Test checkout after the update

After updating, WooCommerce says to test checkout and confirm that Stripe payment methods are available. This is the practical step people skip when they are in a hurry, and it is also the step that catches the problem before customers do.

At minimum, check that the payment options load correctly on checkout and that the store is not throwing errors after the plugin update.

What is known about the risk

WooCommerce says the most significant issue could, under certain circumstances, cause an affected store to become unavailable. That is a business problem even if no payment data is involved: downtime means lost orders, support messages, and possibly a small fire in the inbox.

The advisory also says WooCommerce has no evidence that the issues were exploited and no evidence that store, customer, or payment data was accessed. Technical details are being held back while stores update, which is normal for security advisories where public instructions could help attackers.

Where to read the original advisory

For the patched version table and any later updates, check the original WooCommerce Developer Blog advisory: Security update for Stripe for WooCommerce.

Frequently Asked Questions

Which Stripe for WooCommerce versions need this security update?

WooCommerce says versions 9.7.0 through 10.8.4 are affected. Stores should update to 10.8.5 or the patched build for their current release line.

Is Stripe for WooCommerce 10.8.5 the patched version?

Yes. WooCommerce lists 10.8.5 as the latest patched release for this security update.

Do I need to update again if I already installed the July patch?

Yes. WooCommerce says this update is separate from the July 14 payment validation patch, and stores on 10.6.2, 10.7.1, or 10.8.4 must update again.

Did WooCommerce report any accessed customer or payment data?

No. WooCommerce says it has no evidence that the issues were exploited and no evidence that store, customer, or payment data was accessed.

What should store owners check after updating?

After updating, test checkout and confirm that Stripe payment methods are available. WooCommerce also recommends checking the installed plugin version even if automatic plugin updates are enabled.