Possible security hole in Accept Stripe Payments for WordPress
-
We’ve had hundreds of small fake charges to random people made by our Stripe account. I even got some calls from random people asking why we charged them! This is due to some fraudsters using our Stripe API key for card testing (testing whether a stolen card is valid).
I’m suspecting that the “Accept Stripe Payments” plugin may have some security problem that exposes the API key, because we changed our API key so the fake charges ceased, then configured it in this WordPress plugin to continue accepting Stripe payments in our page, and then we got spammed again with fake charges to random people.
Could the authors of the plugin please look into it?
- The topic ‘Possible security hole in Accept Stripe Payments for WordPress’ is closed to new replies.