Impact
The vulnerability arises from the Stripe Payment Forms by WP Full Pay WordPress plugin's failure to verify that a subscription belongs to the customer associated with the active customer‑portal session. This oversight allows any authenticated user with a confirmed portal session to cancel, reactivate, or modify subscriptions that belong to other customers. The primary impact is the unauthorized alteration of other customers’ subscription states, potentially resulting in financial loss or disruption of service for those customers. Because the flaw does not directly disclose sensitive data, confidentiality impact is limited, but integrity of subscription data is compromised.
Affected Systems
The affected systems are sites running the Stripe Payment Forms by WP Full Pay WordPress plugin, specifically versions prior to 8.5.1. Users who have installed any of these vulnerable plugin versions should consider them at risk.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, but the vulnerability is only exploitable by users with an active, authenticated customer‑portal session. Since it is not listed in CISA's KEV catalog, no known public exploits have been reported yet. Nevertheless, the flaw represents a classic IDOR that could be leveraged by malicious actors to alter other customers' subscriptions, making it a significant integrity concern. The lack of a publicly documented exploit does not reduce the risk: any authenticated user can trigger the behavior by simply accessing endpoints that target a subscription belonging to another customer.
OpenCVE Enrichment