Impact
The vulnerability allows a user who has authenticated to the customer‑portal session to cancel any subscription that belongs to another customer. The plugin does not verify that the subscription being cancelled belongs to the requesting customer, enabling cross‑customer data tampering. This can result in loss of ongoing revenue and disruption of service for innocent customers.
Affected Systems
Any WordPress site that has installed the Stripe Payment Forms by WP Full Pay plugin version 8.5.4 or older is affected. The plugin is used to manage customer‑portal sessions and subscription cancellations, so all users who can access the portal are at risk until the software is updated to 8.5.5 or later.
Risk and Exploitability
Based on the CVSS score of 4.3, the issue is considered low severity, yet it allows a user who is logged into a customer‑portal session to cancel any subscription belonging to another customer. The EPSS score of < 1% suggests that while the likelihood of exploitation is low, it remains a possible threat in targeted attacks. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires knowledge of the target subscription identifier, which is high‑entropy and not enumerated through the plugin’s interface; therefore the attack vector is likely a targeted case where the attacker already knows the subscription ID.
OpenCVE Enrichment