Executive brief
WP Full Stripe Free is a WordPress plugin used to accept payments and manage subscriptions via Stripe. A security flaw in versions 8.4.1 and earlier allows users with basic 'Subscriber' accounts to bypass authentication checks. This could allow an attacker to access sensitive information or perform actions typically reserved for administrators, potentially compromising the website's security and customer data.
Technical details
The WP Full Stripe Free plugin for WordPress is vulnerable to an authentication bypass (CWE-288) in versions up to and including 8.4.1. The flaw resides in the handling of authentication checks, which allows a user with Subscriber-level privileges to bypass intended restrictions. An attacker can exploit this over the network without user interaction to access high-privilege functionality or sensitive data. The vulnerability is classified as 'Broken Authentication' and could potentially lead to full administrative takeover. A fix is available in version 8.4.2.
Affected products
- WP Full Stripe WP Full Stripe Free <= 8.4.1
Timeline
- 2026-04-09: other: Reported by hhhai
- 2026-06-01: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date