Skip to main content

Threat intelligence

STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint

CVE-2026-3640 · strabl-a-checkout-solution

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Strabl A Checkout Solution at a vulnerable version. How SiteRespond intelligence works

Vulnerability
STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint
Affected software
strabl-a-checkout-solution(Plugin)
Affected versions
  • ≤ 4.5
Authentication
Unauthenticated
Vulnerability type
Other
Published
18 June 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 04eb82e4-1738-44c7-980e-8e33a7a3a23a). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Strabl A Checkout Solution version against this catalog when the Defence plugin is connected to your WordPress site.