Impact
The vulnerability allows a user who has authenticated to the customer‑portal session to cancel any subscription that belongs to another customer. The plugin does not verify that the subscription being cancelled belongs to the requesting customer, enabling cross‑customer data tampering. This can result in loss of ongoing revenue and disruption of service for innocent customers.
Affected Systems
Any WordPress site that has installed the Stripe Payment Forms by WP Full Pay plugin version 8.5.4 or older is affected. The plugin is used to manage customer‑portal sessions and subscription cancellations, so all users who can access the portal are at risk until the software is updated to 8.5.5 or later.
Risk and Exploitability
There is no publicly disclosed CVSS score for this issue, but the potential loss of subscription revenue and damage to trust is significant. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires knowledge of the target subscription identifier, which has high entropy and is not easily enumerated through the plugin’s UI. The likely attack vector therefore involves a targeted attack where the attacker already knows the subscription ID, making the exploit theoretically feasible but not trivially scalable.
OpenCVE Enrichment