VYPR
Medium severity6.5NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-42378

CVE-2026-42378

Description

Broken authentication in WP Full Stripe Free <=8.4.1 allows subscribers to escalate privileges to admin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Broken authentication in WP Full Stripe Free <=8.4.1 allows subscribers to escalate privileges to admin.

Vulnerability

The WP Full Stripe Free plugin for WordPress versions 8.4.1 and earlier contains a broken authentication vulnerability [1]. This flaw occurs in the plugin's authentication logic, where subscribers (low-privileged users) are able to perform actions that should be restricted to higher-privileged users, such as administrators. The vulnerability is reachable without any special conditions beyond having a subscriber account on the site.

Exploitation

An attacker with a subscriber account can exploit this vulnerability by sending crafted requests to the affected endpoints. The attacker does not need any additional network position or user interaction beyond being logged in as a subscriber. By abusing the missing or improper capability checks, the attacker can execute actions that are normally available only to higher-privileged users.

Impact

Successful exploitation allows the attacker to perform privileged actions, potentially leading to full administrative access to the WordPress website. This could result in complete compromise of the site, including data theft, site defacement, or installation of malicious plugins. The impact is significant due to the low barrier of entry (a subscriber account) and the high privilege escalation.

Mitigation

The vulnerability is fixed in version 8.4.2, released on an unknown date but available for immediate update [1]. Users are strongly advised to update to version 8.4.2 or later. For those unable to update immediately, Patchstack offers a mitigation rule that blocks attacks until the update is applied [1]. No other workarounds are documented in the available reference.

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1