Impact
The Accept Stripe Payments WordPress plugin, for versions earlier than 2.1.4, does not validate a user‑supplied URL before performing a redirect. The flaw allows an unauthenticated attacker to craft a request that redirects site visitors to an arbitrary external site, which can be used to execute phishing attempts. This type of weakness is a classic open redirect, lacking proper input validation for redirect destinations.
Affected Systems
Vendors: Unknown. Product: Accept Stripe Payments. All releases prior to version 2.1.4 are affected.
Risk and Exploitability
The vulnerability can be triggered by anyone who can reach the plugin’s IPN handler endpoint, with no authentication required. Although no CVSS score is available, the EPSS score is not disclosed and the issue is not listed in the CISA KEV catalog, the low effort required to construct a malicious redirect and the potential for social‑engineering attacks imply a significant risk. An attacker could use the redirect to direct visitors to malicious sites, compromise credentials or deliver malware.
OpenCVE Enrichment