AI News
  • Home
  • Artificial Intelligence
  • E-commerce
  • News
  • Featured
  • Web World
  • Contact
No Result
View All Result
AI News
  • Home
  • Artificial Intelligence
  • E-commerce
  • News
  • Featured
  • Web World
  • Contact
No Result
View All Result
AI News
No Result
View All Result

Card Testing Bots Skip Your Checkout Form. Stop Them

Paul H by Paul H
July 20, 2026
in E-commerce, IT Network, WordPress
5 0
0
Illustration of bot drones firing streams of credit card shapes at an online store gateway, representing card testing attacks
6
SHARES
Summarize with ChatGPTShare to Facebook

Card testing bots don’t fill out your checkout form. They skip it entirely and fire stolen card numbers straight at your store’s API, hundreds per minute, while your CAPTCHA sits there guarding an empty page. That’s the uncomfortable reality for WooCommerce store owners in 2026, and it explains why so many merchants wake up to thousands of $1 failed transactions and a warning email from their payment processor.

Cutaway illustration of card data flowing through an API pipe underneath a storefront checkout, bypassing the checkout form

What a card testing attack actually looks like

Fraudsters buy stolen card numbers in bulk. Before they use them for real purchases, they need to know which ones still work. So they point a bot at a small store’s checkout and run tiny authorization attempts, often $0 or $1, to sort live cards from dead ones. Your store is the testing lab. You pay the price in processing fees, declined-transaction penalties, and a fraud ratio that can get your merchant account terminated.

The scale is growing fast. According to Federal Trade Commission data compiled by Chargeback.io, consumers filed more than 500,000 credit card fraud reports in the first three quarters of 2025, nearly 180,000 more than the same period in 2024. Every one of those stolen cards was likely validated somewhere, and small stores with weak API protection are the preferred venue.

The part most owners miss: modern attacks bypass the checkout page. WooCommerce’s block-based checkout is powered by the Store API, and as the WooCommerce developer team has documented, bots send requests directly to the /wc/store/v1/checkout endpoint. Frontend defenses like CAPTCHA widgets never see the traffic.

Why 2026 raised the stakes

Two changes this year turned card testing from an annoyance into a business risk.

First, the card networks started billing for it. Visa’s Acquirer Monitoring Program (VAMP) now tracks enumeration attacks, the industry term for bots guessing and testing card numbers, and penalizes acquirers whose merchants fail to prevent them, as reported by Practical Ecommerce. Those penalties roll downhill to you. Mastercard, according to payments compliance firm Beast Insights, raised its excessive authorization attempt fee from $0.10 to $0.50 per retry in 2026, a fivefold increase aimed squarely at card testing traffic. A bot that fires 10,000 attempts at your store can now generate real, invoiced costs.

Second, attackers went after the checkout itself. In May 2026, security firm Sansec reported that a flaw in the Funnel Builder plugin, installed on more than 40,000 WooCommerce stores, was under active exploitation. The Hacker News covered the campaign: attackers injected fake Google Tag Manager scripts that loaded payment skimmers on checkout pages, stealing card numbers, CVVs, and billing addresses in real time. The fix shipped in version 3.15.0.3, but stores that hadn’t updated kept leaking customer data. This is the same threat category we covered in our guide to the seven security threats targeting small stores in 2026, and it’s getting worse, not better.

Isometric illustration of a shield with a gauge deflecting a stream of arrows, representing checkout rate limiting

Five defenses that work at the API level

1. Turn on Store API rate limiting

WooCommerce ships with rate limiting built in, and since version 9.6 you can set stricter rules for the place-order endpoint directly from the dashboard, per the WooCommerce developer blog. It’s off by default on many stores. Turn it on. It won’t stop a distributed attack alone, but it kills the lazy ones.

2. Add edge-level rules

If you’re behind Cloudflare or a similar service, create a rate limit on POST requests to your checkout path. Practitioners who clean up these attacks, like the team at Seven Dev, suggest a baseline of 5 to 10 POST requests per IP per minute. Legitimate customers never hit that ceiling. Bots hit it in seconds.

3. Update WooCommerce for fingerprinting

WooCommerce 9.8 added order attribution fingerprinting that combines IP address, user agent, and language headers. Bots rotating through proxy IPs get caught by the other two signals. If you’re running an older version, this alone justifies the update.

4. Audit your checkout plugins this week

The Funnel Builder campaign worked because stores ran outdated plugin versions for weeks after the patch. Check every plugin that touches checkout, and review any “external scripts” settings for entries you don’t recognize. Our roundup of the most popular WordPress plugins is a good reference for what should and shouldn’t be running on a lean store.

5. Use your processor’s fraud tools

They work at scale you can’t match. Stripe reports that its Radar system blocked 20.9 million fraudulent transactions worth $917 million during the 2024 Black Friday period alone (a vendor figure, but a useful signal of volume). Whatever processor you use, enable its velocity checks and CVC verification. If you’re shopping for a processor, our comparison of payment processing fees for Canadian merchants covers what these tools cost at each provider.

Overhead illustration of a merchant desk with a spiking chart and coins sliding into a drain, representing the cost of fraud

What ignoring this costs

LexisNexis Risk Solutions’ True Cost of Fraud study puts the real damage in perspective: U.S. merchants lose $4.61 for every dollar of direct fraud, once you count fees, chargebacks, lost merchandise, and labor. That figure is up 37% from 2020. And card testing compounds with the chargeback problem most stores already have. If your dispute ratio is climbing, our breakdown of the friendly fraud surge hitting 83% of merchants pairs directly with this piece.

The takeaway is simple. Your checkout form is not your checkout. The API behind it is, and that’s where the fight happens now. An hour of configuration this week beats a terminated merchant account next month.

Related guides

  • E-commerce Security in 2026: 7 Threats That Target Small Stores
  • Friendly Fraud Is Up for 83% of Merchants. Now What?
  • Payment Processing Fees Compared for Canadian Merchants
  • Best WordPress Plugins: Top 20 Most Popular Choices

Sources

  • The Hacker News, “Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming” (May 2026): https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html
  • Sansec research on the FunnelKit exploitation campaign: https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited
  • WooCommerce Developer Blog, “Card Testing Attacks and the Store API”: https://developer.woocommerce.com/2024/12/18/card-testing-attacks-and-the-store-api/
  • Chargeback.io, chargeback and card fraud statistics (FTC report data): https://www.chargeback.io/blog/chargeback-statistics
  • Practical Ecommerce, “Visa’s VAMP Could Cost Banks and Merchants”: https://www.practicalecommerce.com/visas-vamp-could-cost-banks-and-merchants
  • Beast Insights, “Card Scheme Compliance 2026”: https://beastinsights.com/blog/card-scheme-compliance
  • Stripe, “The State of Online Fraud”: https://stripe.com/guides/state-of-online-fraud
  • Seven Dev, “How to prevent card testing attacks on WooCommerce sites”: https://www.sevendev.com.au/how-to-prevent-card-testing-attacks-on-woocommerce-sites/

Last reviewed: July 19, 2026

Disclosure: This site may earn commissions from links in this article at no extra cost to you.

Related posts:

Google's Universal Cart Is Live. Is Your Store In It?

3 July Cost Changes Are Quietly Cutting Your Margin

E-commerce Accessibility Checklist for 2026

SummarizeShare2
Paul H

Paul H

An SEO and Content expert having experience working with Enterprise-level corporations as an SEO and Digital Marketing Specialist. Contact me for any type of SEO/SEM, Digital Marketing service- paul@e-commpartners.com

Related Stories

Studio product photo with a hidden metadata panel, illustrating AI product image disclosure rules

Your AI Product Photos Now Need a Hidden Tag

by Paul H
August 11, 2026
0

Amazon now requires a hidden metadata keyword on any listing image containing a photorealistic AI-generated person. Two more disclosure deadlines landed on August 2.

Open turnstile gate with parcels flowing toward a single lit podium, illustrating Amazon removing the Featured Offer eligibility gate

Amazon Opened the Buy Box. Your Margin Pays

by Paul H
August 5, 2026
0

Amazon deleted the seller performance gate on the Featured Offer. Locked-out sellers are now in your ranking pool, and the price floor is the first thing to move.

Shipping cartons on a pallet behind a legal contract page with a padlock, illustrating the Amazon BSA change

Amazon Bans Pledging Your Payouts on Aug 24

by Paul H
August 4, 2026
0

Amazon's revised Business Solutions Agreement takes effect August 24. Pledging your Amazon payouts as collateral becomes prohibited, right as sellers finance Q4 inventory.

Shopping cart on a laptop balanced against a government building on a legal scale

2 States Just Banned Your Pricing Algorithm

by Paul H
August 4, 2026
0

Maryland and New Jersey now ban personalized pricing built on customer data, and phantom discount lawsuits are hitting retailers of every size. Here is the one-afternoon audit that...

Recommended

Amazon fine Italy

Amazon hit with $1.3 billion fine by Italy for abusing it’s position

May 26, 2025
Illustration of a large judge gavel looming over a laptop showing an online store

5,000 ADA Lawsuits Later, Your Widget Won’t Save You

July 18, 2026

Popular Story

  • AI is revolutionizing retail

    The AI Revolution in Retail: Where We Stand Today

    20 shares
    Share 8 Tweet 5
  • Autonomous Deliveries: The Future of eCommerce Logistics and the Rise of Drones and Self-Driving Vehicles

    18 shares
    Share 7 Tweet 5
  • Why use WordPress for your Website?

    17 shares
    Share 7 Tweet 4
  • Top 10 Advanced SEO Techniques & Strategies for 2024

    15 shares
    Share 6 Tweet 4
  • Apple Mac Studio M4 Max Review: Creator Powerhouse

    15 shares
    Share 6 Tweet 4

E-commerce Partners covers the latest in online retail, AI, and digital shopping trends. We publish news, guides, and analysis to help store owners and marketers stay ahead.

Follow us

Recent Posts

Abstract illustration of a single consumer deletion request fanning out to many company data servers on a repeating 45-day cycle

California Delete Act: The $200-a-Day Clock Started

August 3, 2026
Bar chart of AI impressions next to an empty outline representing missing click data

Your Google AI Impressions Are Live. Clicks Aren’t.

August 2, 2026

Weekly Newsletter

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Landing Page
  • Buy JNews
  • Support Forum
  • Pre-sale Question
  • Contact Us

© 2026 E-commerce Partners - E-commerce & AI news .