Junglewise Threat Intelligence

CVE-2026-42752: Stripe Payments bypass vulnerability in WordPress plugin

CVE-2026-42752 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Vendors: Tips and Tricks HQ.

Executive brief

A security vulnerability exists in the Stripe Payments plugin for WordPress, which is used to process credit card payments on websites. An attacker could bypass certain security restrictions or intended workflows without needing to log in. This could potentially lead to unauthorized access to payment-related functions or data, though the overall risk is currently rated as medium.

Technical details

The Stripe Payments plugin for WordPress (versions <= 2.0.98) contains a bypass vulnerability classified under CWE-440 (Expected Behavior Violation). The flaw allows an unauthenticated remote attacker to bypass intended security restrictions or logic checks within the plugin's code. The attack vector is network-based with low complexity and requires no user interaction. Successful exploitation could result in a partial loss of confidentiality and integrity. The issue is addressed in version 2.0.99.

Affected products

  • Tips and Tricks HQ Stripe Payments <= 2.0.98

Timeline

  • 2026-04-29: other: Reported by researcher dodoh4t
  • 2026-05-29: patched: Patch released in version 2.0.99
  • 2026-06-15: disclosed: NVD publication date

References