Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary scripts into web pages that use the WP Full Stripe Free plugin because the plugin does not properly sanitize its output, creating a client‑side Cross Site Scripting flaw (CWE‑79).
Affected Systems
The flaw affects the WordPress plugin WP Full Stripe Free version 8.5.0 and earlier, distributed by Themeisle. Any WordPress site that uses these plugin versions for Stripe payment processing is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 signals high severity. No EPSS score is available, and the plugin is not listed in CISA KEV. Because the vulnerability is unauthenticated, any user can trigger it by accessing a page that renders the vulnerable data, potentially compromising the integrity of the site’s front‑end content.
OpenCVE Enrichment