CVE-2026-62073: WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
Published Oct 1, 2026
·Updated
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Affected Software
1 affected component
WordPress WP Full Stripe Free<=8.5.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Full Stripe Freeto a version that resolves this vulnerability.Fixed in 8.5.7
Event History
Oct 1, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any privileges to exploit it.
2
What is the potential impact?
The available severity vector indicates a network-reachable issue with low attack complexity and no user interaction required. It can affect integrity, while confidentiality and availability impacts are not indicated.
3
Which plugin versions are affected?
WP Full Stripe Free versions 8.5.6 and earlier are identified as affected.