Impact
The WordPress WP Full Stripe Free plugin exposes a flaw that lets unauthenticated users bypass the intended access controls. This allows the attacker to reach functionality or resources that should be protected, potentially altering plugin settings or interacting with the Stripe payment interface without proper authorization. The weakness is characterized as a classic broken access control issue.
Affected Systems
WordPress sites that run the Themeisle WP Full Stripe Free plugin, specifically versions 8.5.6 and older, are affected. The vulnerability exists in the plugin’s code base and is not mitigated by default WordPress security settings unless the plugin itself is updated to version 8.5.7 or later.
Risk and Exploitability
With a CVSS score of 7.5 the threat is considered high severity. The EPSS score is not available, but the lack of a KEV listing indicates that no documented mass exploitation is known at this time. The likely attack vector is a remote unauthenticated request through the plugin’s exposed endpoints, where an attacker can trigger the broken access control to gain unauthorized access. Immediate patching is required to eliminate the vulnerability.
OpenCVE Enrichment