Junglewise Threat Intelligence

CVE-2026-80311: WP Full Pay Stripe Payment Forms IDOR subscription cancellation

CVE-2026-80311 · Severity: medium · CVSS 4.3 · Published 2026-08-29

Executive brief

The Stripe Payment Forms by WP Full Pay WordPress plugin is used to manage customer subscriptions and payments on WordPress sites. A flaw allows an authenticated attacker with a valid customer-portal session to cancel subscriptions belonging to other customers, potentially disrupting service for victims and causing revenue loss. The attack requires knowledge of the victim's subscription ID, which is not directly enumerable through the plugin.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the subscription cancellation endpoint (wp_full_stripe_cancel_my_subscription). The plugin fails to verify that a subscription belongs to the customer associated with the authenticated portal session before processing the cancellation request. An attacker with a confirmed customer-portal session (authenticated via email and security code) can submit a cancellation request targeting a victim's subscription ID. The attack vector is network-based and requires prior authentication as a legitimate customer, but no privilege escalation. Successful exploitation results in unauthorized subscription cancellation in both the plugin database and Stripe. The vulnerability was fixed in version 8.5.5.

Affected products

  • WP Full Pay Stripe Payment Forms before 8.5.5

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: patched: Fixed in version 8.5.5

References

Related threats