Impact
The Accept Stripe Payments WordPress plugin, for versions earlier than 2.1.4, does not validate a user‑supplied URL before performing a redirect. The flaw allows an unauthenticated attacker to craft a request that redirects site visitors to an arbitrary external site, which can be used to execute phishing attempts. Based on the description, this appears to be an open redirect vulnerability; the lack of validation and ability for unauthenticated users to trigger the redirect implies this type of weakness, but the classification as a "classic open redirect" is inferred.
Affected Systems
Vendors: Unknown. Product: Accept Stripe Payments. All releases prior to version 2.1.4 are affected.
Risk and Exploitability
The vulnerability can be triggered by anyone who can reach the plugin’s IPN handler endpoint, with no authentication required. The CVSS score of 4.3 indicates moderate severity, the EPSS score is less than 1%, and it is not listed in the CISA KEV catalog. These metrics suggest that while exploitation effort is low, the potential for social‑engineering attacks and phishing remains significant. An attacker could redirect site visitors to malicious sites to compromise credentials or deliver malware.
OpenCVE Enrichment