Impact
The Easy Stripe WordPress plugin contains a code injection defect that permits a remote attacker to insert and execute arbitrary PHP code, granting full remote code execution on the web server. This flaw is a classic example of CWE‑94, where the application does not adequately sanitize or validate user-supplied code that is later evaluated.
Affected Systems
The vulnerability applies to the Easy Stripe plugin developed by Scott Paterson, specifically versions up to and including 1.1. WordPress sites that have installed any of these affected versions are exposed; no other products or modules are listed as impacted.
Risk and Exploitability
The exploit carries a CVSS score of 10, indicating the highest severity. The EPSS score is reported as less than 1%, implying a very low current exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector involves any authenticated or unauthenticated user who can inject code via the plugin’s input mechanisms, allowing the attacker to run arbitrary PHP code.
OpenCVE Enrichment
EUVD