PT-2026-53054 · WordPress · Wp Full Stripe Free

·

CVE-2026-12432

·

Published

2026-06-27

·

Updated

2026-06-27

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Full Stripe Free versions prior to 8.4.4
Description The plugin contains a missing authorization flaw in the wpfs update failed payment status AJAX action. The update failed payment status() function fails to perform capability checks, nonce verification, or login requirements before executing $this->db->updatePaymentByEventId() using attacker-controlled POST parameters. Unauthenticated attackers with a valid Stripe Payment Intent ID can manipulate database payment records, marking successful payments as failed and overwriting failure codes and messages.
Recommendations Update WP Full Stripe Free to version 8.4.4 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12432

Affected Products

Wp Full Stripe Free