Executive brief
The Stripe Payments WordPress plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into affected websites. An attacker can exploit this to steal visitor data, hijack user accounts, or redirect visitors to malicious sites. This affects all installations running version 2.1.2 and earlier, and the patch is available in version 2.1.3.
Technical details
This is an unauthenticated stored or reflected XSS vulnerability in the Stripe Payments WordPress plugin versions up to 2.1.2. The vulnerability allows attackers to inject arbitrary JavaScript code that executes in the context of affected users' browsers without requiring authentication. Successful exploitation requires user interaction (such as a visitor clicking a malicious link or viewing a crafted page), but this is trivially achievable through social engineering or mass distribution. An attacker can steal sensitive data, session tokens, or perform actions on behalf of victims. The vulnerability is patched in version 2.1.3 and later.
Affected products
- Stripe Payments Stripe Payments <= 2.1.2
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Version 2.1.3 released