Card testing bots don’t fill out your checkout form. They skip it entirely and fire stolen card numbers straight at your store’s API, hundreds per minute, while your CAPTCHA sits there guarding an empty page. That’s the uncomfortable reality for WooCommerce store owners in 2026, and it explains why so many merchants wake up to thousands of $1 failed transactions and a warning email from their payment processor.

What a card testing attack actually looks like
Fraudsters buy stolen card numbers in bulk. Before they use them for real purchases, they need to know which ones still work. So they point a bot at a small store’s checkout and run tiny authorization attempts, often $0 or $1, to sort live cards from dead ones. Your store is the testing lab. You pay the price in processing fees, declined-transaction penalties, and a fraud ratio that can get your merchant account terminated.
The scale is growing fast. According to Federal Trade Commission data compiled by Chargeback.io, consumers filed more than 500,000 credit card fraud reports in the first three quarters of 2025, nearly 180,000 more than the same period in 2024. Every one of those stolen cards was likely validated somewhere, and small stores with weak API protection are the preferred venue.
The part most owners miss: modern attacks bypass the checkout page. WooCommerce’s block-based checkout is powered by the Store API, and as the WooCommerce developer team has documented, bots send requests directly to the /wc/store/v1/checkout endpoint. Frontend defenses like CAPTCHA widgets never see the traffic.
Why 2026 raised the stakes
Two changes this year turned card testing from an annoyance into a business risk.
First, the card networks started billing for it. Visa’s Acquirer Monitoring Program (VAMP) now tracks enumeration attacks, the industry term for bots guessing and testing card numbers, and penalizes acquirers whose merchants fail to prevent them, as reported by Practical Ecommerce. Those penalties roll downhill to you. Mastercard, according to payments compliance firm Beast Insights, raised its excessive authorization attempt fee from $0.10 to $0.50 per retry in 2026, a fivefold increase aimed squarely at card testing traffic. A bot that fires 10,000 attempts at your store can now generate real, invoiced costs.
Second, attackers went after the checkout itself. In May 2026, security firm Sansec reported that a flaw in the Funnel Builder plugin, installed on more than 40,000 WooCommerce stores, was under active exploitation. The Hacker News covered the campaign: attackers injected fake Google Tag Manager scripts that loaded payment skimmers on checkout pages, stealing card numbers, CVVs, and billing addresses in real time. The fix shipped in version 3.15.0.3, but stores that hadn’t updated kept leaking customer data. This is the same threat category we covered in our guide to the seven security threats targeting small stores in 2026, and it’s getting worse, not better.

Five defenses that work at the API level
1. Turn on Store API rate limiting
WooCommerce ships with rate limiting built in, and since version 9.6 you can set stricter rules for the place-order endpoint directly from the dashboard, per the WooCommerce developer blog. It’s off by default on many stores. Turn it on. It won’t stop a distributed attack alone, but it kills the lazy ones.
2. Add edge-level rules
If you’re behind Cloudflare or a similar service, create a rate limit on POST requests to your checkout path. Practitioners who clean up these attacks, like the team at Seven Dev, suggest a baseline of 5 to 10 POST requests per IP per minute. Legitimate customers never hit that ceiling. Bots hit it in seconds.
3. Update WooCommerce for fingerprinting
WooCommerce 9.8 added order attribution fingerprinting that combines IP address, user agent, and language headers. Bots rotating through proxy IPs get caught by the other two signals. If you’re running an older version, this alone justifies the update.
4. Audit your checkout plugins this week
The Funnel Builder campaign worked because stores ran outdated plugin versions for weeks after the patch. Check every plugin that touches checkout, and review any “external scripts” settings for entries you don’t recognize. Our roundup of the most popular WordPress plugins is a good reference for what should and shouldn’t be running on a lean store.
5. Use your processor’s fraud tools
They work at scale you can’t match. Stripe reports that its Radar system blocked 20.9 million fraudulent transactions worth $917 million during the 2024 Black Friday period alone (a vendor figure, but a useful signal of volume). Whatever processor you use, enable its velocity checks and CVC verification. If you’re shopping for a processor, our comparison of payment processing fees for Canadian merchants covers what these tools cost at each provider.

What ignoring this costs
LexisNexis Risk Solutions’ True Cost of Fraud study puts the real damage in perspective: U.S. merchants lose $4.61 for every dollar of direct fraud, once you count fees, chargebacks, lost merchandise, and labor. That figure is up 37% from 2020. And card testing compounds with the chargeback problem most stores already have. If your dispute ratio is climbing, our breakdown of the friendly fraud surge hitting 83% of merchants pairs directly with this piece.
The takeaway is simple. Your checkout form is not your checkout. The API behind it is, and that’s where the fight happens now. An hour of configuration this week beats a terminated merchant account next month.
Related guides
- E-commerce Security in 2026: 7 Threats That Target Small Stores
- Friendly Fraud Is Up for 83% of Merchants. Now What?
- Payment Processing Fees Compared for Canadian Merchants
- Best WordPress Plugins: Top 20 Most Popular Choices
Sources
- The Hacker News, “Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming” (May 2026): https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html
- Sansec research on the FunnelKit exploitation campaign: https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited
- WooCommerce Developer Blog, “Card Testing Attacks and the Store API”: https://developer.woocommerce.com/2024/12/18/card-testing-attacks-and-the-store-api/
- Chargeback.io, chargeback and card fraud statistics (FTC report data): https://www.chargeback.io/blog/chargeback-statistics
- Practical Ecommerce, “Visa’s VAMP Could Cost Banks and Merchants”: https://www.practicalecommerce.com/visas-vamp-could-cost-banks-and-merchants
- Beast Insights, “Card Scheme Compliance 2026”: https://beastinsights.com/blog/card-scheme-compliance
- Stripe, “The State of Online Fraud”: https://stripe.com/guides/state-of-online-fraud
- Seven Dev, “How to prevent card testing attacks on WooCommerce sites”: https://www.sevendev.com.au/how-to-prevent-card-testing-attacks-on-woocommerce-sites/
Last reviewed: July 19, 2026
Disclosure: This site may earn commissions from links in this article at no extra cost to you.









