Impact
The vulnerability lies in a failure to verify that a customer-portal session has completed its confirmation step before returning data, allowing unauthenticated users to retrieve subscription and billing data belonging to other customers. The result is unauthorized disclosure of private financial information. This weakness aligns with sensitive data exposure (CWE-200).
Affected Systems
The affected product is the Stripe Payment Forms by WP Full Pay WordPress plugin. Versions prior to 8.5.1 are impacted. The plugin is commonly installed on WordPress sites that enable customer portals for Stripe payment processing.
Risk and Exploitability
The vulnerability can be exploited by any external actor simply by accessing the customer-portal endpoint, without authentication or special privileges. The likely attack vector is an unauthenticated HTTP request to the portal endpoint. The CVSS score of 5.3 indicates a medium‑impact flaw, while the EPSS score of < 1% suggests low current exploitation probability. Because the issue is not listed in the CISA KEV catalog, exploitation remains unlikely, but the sensitivity of the exposed data and the ease of access imply a moderate risk.
OpenCVE Enrichment