CVE-2026-78282: WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Stripe Payments Pluginto a version that resolves this vulnerability.Fixed in 2.1.3
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated XSS, so the attacker does not need a WordPress or plugin account. The CVSS vector indicates user interaction is required, meaning exploitation requires a victim to interact with attacker-controlled content or a crafted request.
What versions are affected?
Stripe Payments versions 2.1.2 and earlier are identified as affected. The provided data does not identify a fixed version.
What is the potential impact?
The supplied CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. Successful XSS may allow attacker-controlled script execution in a victim's browser context after the required user interaction.