Impact
The vulnerability lies in failed verification of a customer‑portal session’s confirmation step, permitting unauthenticated users to retrieve subscription and billing data belonging to other customers. The result is unauthorized disclosure of private financial information. This weakness aligns with improper access control and session validation flaws, classified under CWE‑284.
Affected Systems
The affected product is the Stripe Payment Forms by WP Full Pay WordPress plugin. Versions prior to 8.5.1 are impacted. The plugin is commonly installed on WordPress sites that enable customer portals for Stripe payment processing.
Risk and Exploitability
The vulnerability can be exploited by any external actor simply by accessing the customer‑portal endpoint, without authentication or special privileges. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the current exploitation likelihood is unknown, but the ease of access and the sensitivity of the exposed data imply a high risk. A CVSS score is not provided, but the nature of the flaw suggests a strong potential for significant confidentiality loss.
OpenCVE Enrichment