Description
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
Published: 2026-08-26
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass: modification of other customers' subscriptions
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the Stripe Payment Forms by WP Full Pay WordPress plugin's failure to verify that a subscription belongs to the customer associated with the active customer‑portal session. This oversight allows any authenticated user with a confirmed portal session to cancel, reactivate, or modify subscriptions that belong to other customers. The primary impact is the unauthorized alteration of other customers’ subscription states, potentially resulting in financial loss or disruption of service for those customers. Because the flaw does not directly disclose sensitive data, confidentiality impact is limited, but integrity of subscription data is compromised.

Affected Systems

The affected systems are sites running the Stripe Payment Forms by WP Full Pay WordPress plugin, specifically versions prior to 8.5.1. Users who have installed any of these vulnerable plugin versions should consider them at risk.

Risk and Exploitability

The CVSS score is 4.3, and the EPSS score is < 1%. The vulnerability is only exploitable by users with an active, authenticated customer‑portal session. Since it is not listed in CISA's KEV catalog, no known public exploits have been reported yet. Nevertheless, the flaw represents a classic IDOR that could be leveraged by malicious actors to alter other customers' subscriptions, making it a significant integrity concern. The lack of a publicly documented exploit does not reduce the risk: any authenticated user can trigger the behavior by simply accessing endpoints that target a subscription belonging to another customer.

Generated by OpenCVE AI on August 26, 2026 at 20:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Stripe Payment Forms by WP Full Pay plugin to version 8.5.1 or later
  • If the update cannot be applied immediately, disable subscription modification actions in the customer portal until the patch is installed
  • Monitor access logs for unusual subscription cancellation or modification activity and investigate any unauthorized changes

Generated by OpenCVE AI on August 26, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other customers.
Title Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T14:43:07.191Z

Reserved: 2026-08-21T12:09:00.836Z

Link: CVE-2026-77789

cve-icon Vulnrichment

Updated: 2026-08-26T14:37:56.271Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T06:16:29.810

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-77789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:30:11Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key