VYPR
Unrated severityNVD Advisory· Published Jul 17, 2022· Updated Aug 3, 2024

Accept Stripe Payments < 2.0.64 - Admin+ Stored Cross-Site Scripting

CVE-2022-2194

Description

Admin+ stored XSS in Accept Stripe Payments plugin < 2.0.64 allows script injection even with unfiltered_html disallowed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Admin+ stored XSS in Accept Stripe Payments plugin < 2.0.64 allows script injection even with unfiltered_html disallowed.

Vulnerability

The Accept Stripe Payments WordPress plugin before version 2.0.64 [1] fails to sanitize and escape some of its settings. This allows high-privilege users, such as administrators, to inject arbitrary web scripts. The vulnerability is a stored cross-site scripting (XSS) issue that can be triggered even when the unfiltered_html capability is disallowed [1].

Exploitation

An attacker with administrator-level access can exploit this vulnerability by injecting malicious script code into the plugin settings. The injected script will be stored and executed when any user (including other admins) views the affected settings page. The attacker does not need special permissions beyond administrative access to the WordPress dashboard [1].

Impact

Successful exploitation results in persistent execution of arbitrary JavaScript in the context of the admin interface. This can lead to session hijacking, defacement, or further compromise of the WordPress site. The attacker's script runs with the privileges of the victim's browser session, potentially allowing actions such as creating new admin accounts or modifying site content [1].

Mitigation

The vulnerability is fixed in version 2.0.64 of the Accept Stripe Payments plugin [1]. Users should update to this version immediately. No workarounds are provided in the advisory. There is no indication that this CVE is listed in the Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.