Junglewise Threat Intelligence

CVE-2026-8893: WordPress Express Payment For Stripe Stored XSS in shortcode

CVE-2026-8893 · Severity: medium · CVSS 6.4 · Published 2026-06-06

Vendors: Wordpress.

Executive brief

The Express Payment For Stripe plugin for WordPress, which allows websites to accept payments via Stripe, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into pages. These scripts will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.

Technical details

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'type' attribute of the [stripe-express] shortcode. The vulnerability exists within the register_shortcode() function, where the attribute value is concatenated directly into an HTML attribute without being processed by esc_attr() or similar escaping functions. An authenticated attacker with contributor-level permissions or higher can exploit this to inject arbitrary web scripts into a page. These scripts are then stored and executed in the context of any user's browser who visits the compromised page. The issue is addressed in versions following 1.28.0.

Affected products

  • WordPress Express Payment For Stripe up to, and including, 1.28.0

Timeline

  • 2026-06-06: advisory: NVD publication date

References