VYPR

Stripe Payment Forms by WP Full Pay

by WordPress

CVEs (1)

  • CVE-2026-16734Aug 6, 2026
    risk 0.00cvss epss 0.00

    The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every…