Description
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Broken Access Control
Action: Immediate Patch
AI Analysis

Impact

The WordPress WP Full Stripe Free plugin exposes a flaw that lets unauthenticated users bypass the intended access controls. This allows the attacker to reach functionality or resources that should be protected, potentially altering plugin settings or interacting with the Stripe payment interface without proper authorization. The weakness is characterized as a classic broken access control issue.

Affected Systems

WordPress sites that run the Themeisle WP Full Stripe Free plugin, specifically versions 8.5.6 and older, are affected. The vulnerability exists in the plugin’s code base and is not mitigated by default WordPress security settings unless the plugin itself is updated to version 8.5.7 or later.

Risk and Exploitability

With a CVSS score of 7.5 the threat is considered high severity. The EPSS score is not available, but the lack of a KEV listing indicates that no documented mass exploitation is known at this time. The likely attack vector is a remote unauthenticated request through the plugin’s exposed endpoints, where an attacker can trigger the broken access control to gain unauthorized access. Immediate patching is required to eliminate the vulnerability.

Generated by OpenCVE AI on October 1, 2026 at 15:24 UTC.

Remediation

Vendor Solution

Update the WordPress WP Full Stripe Free plugin to the latest available version (at least 8.5.7).


OpenCVE Recommended Actions

  • Update the WP Full Stripe Free plugin to version 8.5.7 or later.
  • Review the plugin’s configuration to confirm that only authorized user roles can execute its features.
  • Restrict access to the plugin’s administrative interface by ensuring only trusted users have the necessary capabilities.

Generated by OpenCVE AI on October 1, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Title WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T14:33:54.117Z

Reserved: 2026-07-13T06:14:52.917Z

Link: CVE-2026-62073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:30.797

Modified: 2026-10-01T15:17:30.797

Link: CVE-2026-62073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses