Description
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the Stripe Payment Forms by WP Full Pay WordPress plugin's failure to verify that a subscription belongs to the customer associated with the active customer‑portal session. This oversight allows any authenticated user with a confirmed portal session to cancel, reactivate, or modify subscriptions that belong to other customers. The primary impact is the unauthorized alteration of other customers’ subscription states, potentially resulting in financial loss or disruption of service for those customers. Because the flaw does not directly disclose sensitive data, confidentiality impact is limited, but integrity of subscription data is compromised.

Affected Systems

The affected systems are sites running the Stripe Payment Forms by WP Full Pay WordPress plugin, specifically versions prior to 8.5.1. Users who have installed any of these vulnerable plugin versions should consider them at risk.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, but the vulnerability is only exploitable by users with an active, authenticated customer‑portal session. Since it is not listed in CISA's KEV catalog, no known public exploits have been reported yet. Nevertheless, the flaw represents a classic IDOR that could be leveraged by malicious actors to alter other customers' subscriptions, making it a significant integrity concern. The lack of a publicly documented exploit does not reduce the risk: any authenticated user can trigger the behavior by simply accessing endpoints that target a subscription belonging to another customer.

Generated by OpenCVE AI on August 26, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Stripe Payment Forms by WP Full Pay plugin to version 8.5.1 or later
  • If the update cannot be applied immediately, disable subscription modification actions in the customer portal until the patch is installed
  • Monitor access logs for unusual subscription cancellation or modification activity and investigate any unauthorized changes

Generated by OpenCVE AI on August 26, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
Title Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T14:43:07.191Z

Reserved: 2026-08-21T12:09:00.836Z

Link: CVE-2026-77789

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:30:16Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key