The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers.
Exploitation requires the attacker to know the target subscription's identifier, which is high-entropy and not enumerable through the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5.
Metrics
Affected Vendors & Products
References
History
Sun, 30 Aug 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sun, 30 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Sat, 29 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sat, 29 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation requires the attacker to know the target subscription's identifier, which is high-entropy and not enumerable through the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5. | |
| Title | Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via IDOR | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-29T06:00:23.240Z
Updated: 2026-08-30T00:56:50.898Z
Reserved: 2026-08-26T08:29:53.085Z
Link: CVE-2026-80311
Updated: 2026-08-30T00:48:41.079Z
Status : Deferred
Published: 2026-08-29T06:17:49.560
Modified: 2026-08-31T20:14:36.250
Link: CVE-2026-80311
No data.