CVE-2025-49302: WordPress Easy Stripe plugin <= 1.1 - Remote Code Execution (RCE) Vulnerability
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects Easy Stripe: from n/a through 1.1.
Other sources
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows Remote Code Inclusion.This issue affects Easy Stripe: from n/a through <= 1.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49302?
CVE-2025-49302 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-49302?
The recommended fix for CVE-2025-49302 is to update Easy Stripe to the latest version beyond 1.1.
What is the impact of CVE-2025-49302?
CVE-2025-49302 allows for remote code inclusion, which can lead to unauthorized access and control of the affected system.
Who is affected by CVE-2025-49302?
CVE-2025-49302 affects users of Scott Paterson Easy Stripe and WordPress Easy Stripe versions up to 1.1.
Is CVE-2025-49302 actively being exploited?
There have been indications that CVE-2025-49302 is being actively exploited in the wild.