Description
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unchecked, causing getErrorMessage() to return the raw Stripe error string unchanged rather than substituting a mapped safe message.
Published: 2026-10-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Update Plugin
AI Analysis

Impact

The Payment Plugins for Stripe WooCommerce plugin contains a reflected cross‑site scripting flaw triggered by a URL fragment containing a "#response" token. The vulnerability stems from insufficient sanitization and escaping when the plugin outputs raw Stripe error messages. An attacker can inject JavaScript that will run in the context of the target site whenever a user visits a crafted URL containing the malicious fragment. The flaw permits unauthenticated code execution that can lead to data theft, session hijacking, or defacement, but only on pages rendered through the affected plugin. This weakness is identified in CWE‑79.

Affected Systems

WordPress sites that run Payment Plugins for Stripe WooCommerce version 4.0.17 or earlier are vulnerable. The issue applies to all builds up to and including 4.0.17. Versions released after 4.0.17 contain a fix that sanitizes the fragment and maps Stripe error strings to safe messages.

Risk and Exploitability

The CVSS score of 6.1 classifies the issue as moderate. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation reports exist at this time. Exploitation requires an attacker to entice a victim to visit a URL that includes a crafted '#response' fragment; no authentication or elevated privileges are needed. Because the flaw is reflected and operates on untrusted user input, a successful exploit will execute the injected script in the victim’s browser while authenticated with the site’s normal permissions.

Generated by OpenCVE AI on October 10, 2026 at 09:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payment Plugins for Stripe WooCommerce to the latest version (4.0.18 or newer).
  • After upgrading, ensure that the plugin’s settings enforce sanitized error handling and do not display raw Stripe error strings.
  • If upgrading is not immediately possible, modify the plugin’s source files to escape or strip the '#response' fragment before rendering output to prevent script injection.

Generated by OpenCVE AI on October 10, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unchecked, causing getErrorMessage() to return the raw Stripe error string unchanged rather than substituting a mapped safe message.
Title Payment Plugins for Stripe WooCommerce <= 4.0.17 - Reflected DOM-Based Cross-Site Scripting via '#response' URL Fragment
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:11.010Z

Reserved: 2026-09-10T21:36:48.568Z

Link: CVE-2026-89100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:41.927

Modified: 2026-10-10T07:16:41.927

Link: CVE-2026-89100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')