Google runs two products under the reCAPTCHA name, in two consoles, with two different verification APIs. Here is how to tell which one your keys belong to, and what follows from that.
WooCommerce records where each order came from, but the browser collects that data and submits it with the order. What the fields are, and what an odd profile is actually worth.
A WordPress nonce is not used once. It is valid for a window, and a cached checkout page carries one minted for somebody else. Your own test order passes because you are signed in.
One key is meant to be read by anyone, the other by nobody. Google’s error codes say which half is wrong, so guessing is never necessary.
The form is on the checkout page. The request that places the order is not, and anything wired to the page template never sees it.
WooCommerce ships a second payment surface for orders that already exist. It calls your gateway directly, and none of your checkout validation runs there.
Google gives a token two minutes and one verification. A checkout that takes longer than that fails honest shoppers, and the error code says so.
WooCommerce treats one page as the checkout. Any other page carrying the form can still place orders, and a captcha wired to the assigned page never sees them.
Google says the score is a risk signal, not a verdict. Here is how to read reCAPTCHA v3 scores on your own traffic and pick a threshold that does not cost you real orders.