PT-2026-68401 · WordPress · Stripe Payment Forms

·

CVE-2026-16734

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Stripe Payment Forms by WP Full Pay versions prior to 8.5.2
Description An issue exists where the plugin fails to verify if the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions. This allows an unauthenticated visitor, using a nonce embedded in public pages with payment forms, to manipulate the amount of a payment intent. The plugin then updates this amount server-side via the Stripe API using the store's secret key. Specifically, the pricing-recalculation and payment-intent-update actions remain unprotected against this amount manipulation.
Recommendations Update Stripe Payment Forms by WP Full Pay to version 8.5.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16734

Affected Products

Stripe Payment Forms