The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
History

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.
Title Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-09-05T06:00:06.632Z

Updated: 2026-09-06T10:39:36.767Z

Reserved: 2026-08-26T19:08:06.347Z

Link: CVE-2026-81424

cve-icon Vulnrichment

Updated: 2026-09-06T10:30:38.272Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T07:17:12.997

Modified: 2026-09-08T19:09:21.310

Link: CVE-2026-81424

cve-icon Redhat

No data.