PT-2026-68401 · WordPress · Stripe Payment Forms
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Stripe Payment Forms by WP Full Pay versions prior to 8.5.2
Description
An issue exists where the plugin fails to verify if the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions. This allows an unauthenticated visitor, using a nonce embedded in public pages with payment forms, to manipulate the amount of a payment intent. The plugin then updates this amount server-side via the Stripe API using the store's secret key. Specifically, the
pricing-recalculation and payment-intent-update actions remain unprotected against this amount manipulation.Recommendations
Update Stripe Payment Forms by WP Full Pay to version 8.5.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stripe Payment Forms