Description
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to inject arbitrary scripts into web pages that use the WP Full Stripe Free plugin because the plugin does not properly sanitize its output, creating a client‑side Cross Site Scripting flaw (CWE‑79).

Affected Systems

The flaw affects the WordPress plugin WP Full Stripe Free version 8.5.0 and earlier, distributed by Themeisle. Any WordPress site that uses these plugin versions for Stripe payment processing is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 signals high severity. No EPSS score is available, and the plugin is not listed in CISA KEV. Because the vulnerability is unauthenticated, any user can trigger it by accessing a page that renders the vulnerable data, potentially compromising the integrity of the site’s front‑end content.

Generated by OpenCVE AI on August 13, 2026 at 16:30 UTC.

Remediation

Vendor Solution

Update the WordPress WP Full Stripe Free Plugin to the latest available version (at least 8.5.1).


OpenCVE Recommended Actions

  • Upgrade WP Full Stripe Free to version 8.5.1 or later
  • If a valid upgrade cannot be applied immediately, disable or remove the plugin as a temporary measure
  • Add a Content Security Policy that disallows inline scripts to mitigate remaining XSS vectors

Generated by OpenCVE AI on August 13, 2026 at 16:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeisle
Themeisle wp Full Stripe Free
Wordpress
Wordpress wordpress
Vendors & Products Themeisle
Themeisle wp Full Stripe Free
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
Title WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themeisle Wp Full Stripe Free
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:48:12.794Z

Reserved: 2026-07-13T06:13:44.978Z

Link: CVE-2026-61960

cve-icon Vulnrichment

Updated: 2026-08-13T14:25:05.575Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:17:02.420

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-61960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')