← All posts

WP User Manager Flaw Can Redirect Your Stripe Payments

· Watch on YouTube

A flaw in WP User Manager could send your customers’ payments into an attacker’s Stripe account, and they don’t need administrator access to do it. But here’s the part that updating alone won’t answer: did somebody change your payment settings before you installed the fix?

I’ve spent 25 years building production software and manage hundreds of WordPress websites. Today, we’re looking at five vulnerabilities, what they could mean for your business, and what you need to check beyond the update button.

Let’s start with your payments. An attacker doesn’t need to shut down your website to stop your business receiving the money. Imagine a customer joining your paid membership site. They enter their credit card details, the payment goes through, but the account receiving it isn’t yours.

That’s the risk with this WP User Manager flaw. Someone with a basic subscriber account could replace the site’s Stripe connection, and future payments could then go to their account instead.

So, update WP User Manager to version 2.9.20 or later. Then check which Stripe account is actually connected, and compare recent membership payments with the transactions in your own Stripe account. Installing the fix and checking where the money went are two different jobs.

Next up, your website can look completely normal while somebody copies information they shouldn’t have. Think of someone opening your filing cabinet. They copy the documents, then put everything back. Nothing looks disturbed, but the information is no longer private.

That’s the concern with Divi Essential. A basic subscriber account could read sensitive information from the WordPress database, and that includes user details and secret keys connecting your website to other services.

So, update Divi Essential to 5.9.0 or later, and have your web team investigate any suspected access to that information. If a secret key was exposed, replace it, because updating the plugin doesn’t take back a copy somebody already made.

Next up, a product filter should help customers choose what to buy, not choose which files your server runs. A visitor is supposed to ask, “Show me the blue shirts,” not, “Open this file on your server.” But that’s the boundary this HUSKY flaw can cross.

HUSKY is a product filter plugin for WooCommerce. An attacker doesn’t need to log in. They can make the plugin load a PHP file already on the server and then run the code inside it.

This does not upload a malicious file by itself. The damage depends on which files are already there and what those files do.

So, update HUSKY to version 1.4.5 or later. Then test your shop’s filters and have any suspicious files investigated by your web team. Fixing the plugin doesn’t remove a dangerous file that was already there.

Next up, an attacker doesn’t need to take over your whole website to stop your marketing working. Imagine paying for a campaign. People click your advertisement, but your sales page has been moved to the trash. You’re still paying for the traffic, but the page they need is no longer there.

That’s the business risk with this WP Table Builder flaw. Someone allowed to use the plugin could trash pages and posts they don’t own, and that can include a subscriber if their role has been given access to the plugin.

So, this isn’t a random visitor attack, but permission to manage tables shouldn’t mean permission to remove your sales page. Update WP Table Builder to version 2.2.2 or later. Check who can use the plugin and review any pages or posts unexpectedly moved to the trash.

And finally, a donation message shouldn’t become a way into your website. When somebody makes a donation, they may send an eCard to let a friend know. It looks like a simple message, but the website still has to process the information behind it.

In Give Tributes, specially crafted form data can be processed unsafely. No login is required, but several conditions must line up. The form must allow multiple recipients, its custom message option must be turned off, and another installed plugin or theme must provide the extra code needed to complete the attack.

In that combination, the flaw could expose private information or allow code to run on your server. So, update Give Tributes to version 2.3.1.1.1 or later. Then check the eCard settings and test your donation form.

This is the Give Tributes add-on. It doesn’t mean every GiveWP site has this particular vulnerability.

So the question today isn’t just, did I update the plugin? It’s, what could somebody have changed before I did? Check the software you actually use, apply the fixes, then check what those flaws could have touched: your payments, your private information, your files and pages.

Finding a vulnerability doesn’t prove you’ve been hacked, and installing the fix doesn’t prove you haven’t. Secure the site, investigate whether exposure warrants it, and if you use WP User Manager, make sure the next payment is actually going to you.