Impact
The Payment Plugins for Stripe WooCommerce plugin contains a reflected cross‑site scripting flaw triggered by a URL fragment containing a "#response" token. The vulnerability stems from insufficient sanitization and escaping when the plugin outputs raw Stripe error messages. An attacker can inject JavaScript that will run in the context of the target site whenever a user visits a crafted URL containing the malicious fragment. The flaw permits unauthenticated code execution that can lead to data theft, session hijacking, or defacement, but only on pages rendered through the affected plugin. This weakness is identified in CWE‑79.
Affected Systems
WordPress sites that run Payment Plugins for Stripe WooCommerce version 4.0.17 or earlier are vulnerable. The issue applies to all builds up to and including 4.0.17. Versions released after 4.0.17 contain a fix that sanitizes the fragment and maps Stripe error strings to safe messages.
Risk and Exploitability
The CVSS score of 6.1 classifies the issue as moderate. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation reports exist at this time. Exploitation requires an attacker to entice a victim to visit a URL that includes a crafted '#response' fragment; no authentication or elevated privileges are needed. Because the flaw is reflected and operates on untrusted user input, a successful exploit will execute the injected script in the victim’s browser while authenticated with the site’s normal permissions.
OpenCVE Enrichment