Junglewise Threat Intelligence

CVE-2026-77758: Stripe Payment Forms by WP Full Pay authentication bypass in customer portal

CVE-2026-77758 · Severity: medium · CVSS 5.3 · Published 2026-08-26

Executive brief

The Stripe Payment Forms by WP Full Pay WordPress plugin allows unauthenticated attackers to access sensitive customer billing and subscription data by exploiting an incomplete session verification in the customer portal. An attacker with only a victim's email address can retrieve subscription details, plan information, and billing records without proper authentication, exposing customer financial information and payment history.

Technical details

The vulnerability is an authentication bypass (CWE-200: Sensitive Data Exposure) in the customer portal session handling. The plugin creates a portal session from an email address alone but fails to verify that the session has completed its emailed security code confirmation step before returning subscription data via the REST API endpoint `/wp-json/wp-full-stripe/v1/manage-subscriptions/subscription`. An unauthenticated attacker can call the `wp_full_stripe_create_card_update_session` AJAX action with a victim's email and then use the resulting session cookie to retrieve sensitive subscription and billing records. The attack requires only knowledge of a victim's email address and access to the WordPress AJAX endpoint, with no further authentication needed. The vulnerability was fixed in version 8.5.1.

Affected products

  • WP Full Pay Stripe Payment Forms by WP Full Pay before 8.5.1

Timeline

  • 2026-08-24: disclosed
  • 2026-08-26: advisory
  • 2026-08-26: patched: Fixed in version 8.5.1

References