CVE-2026-77758: Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.
Affected Software
Event History
Frequently Asked Questions
What must an attacker have to access another customer's information?
The attacker must be able to obtain or use a customer portal session that has not completed its confirmation step. The available data does not state how such an unconfirmed session may be acquired.
Is authentication required to exploit this issue?
No. The issue allows unauthenticated users to read another customer's subscription and billing information when the affected unconfirmed customer portal session condition is present.
Which installations should be remediated?
WordPress sites using Stripe Payment Forms by WP Full Pay versions earlier than 8.5.1 should be remediated. Version 8.5.1 is the first version identified as not affected by the provided information.