The Accept Stripe Payments WordPress plugin before 2.1.4...
Moderate severity
Unreviewed
Published
Sep 5, 2026
to the GitHub Advisory Database
•
Updated Sep 6, 2026
Description
Published by the National Vulnerability Database
Sep 5, 2026
Published to the GitHub Advisory Database
Sep 5, 2026
Last updated
Sep 6, 2026
The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
References