Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in WordPress Stripe Payments Plugin versions up to 2.1.2. The flaw allows an attacker to inject arbitrary JavaScript that will execute in the context of site users or administrators. This could compromise confidentiality and integrity of data accessed by the session.
Affected Systems
The flaw affects the WordPress Stripe Payments plugin from vendor mra13, specifically all releases up to and including version 2.1.2. Sites running these plugin versions without the available patch are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, implying no known widespread exploitation. The attack vector is unauthenticated, meaning any visitor can manipulate input fields that the plugin processes, and the flaw permits arbitrary code execution without additional privileges, raising significant risk to users and site administrators.
OpenCVE Enrichment