CVE-2026-77789: Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs a confirmed customer-portal session. The issue does not require the targeted subscription to belong to that logged-in customer.
Which subscription actions could an attacker perform against another customer?
An attacker with a confirmed portal session could cancel, reactivate, or modify subscriptions belonging to other customers.
Which plugin versions are affected?
WP Full Pay Stripe Payment Forms versions before 8.5.1 are affected. Version 8.5.1 is the first version identified as not affected by the provided information.