Extension WordPress
Vulnérabilités Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
Cette page rassemble les failles publiées pour Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
7 fiches
Stripe Payment Forms by WP Full Pay <= 8.4.3 – Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…
*-8.4.3
8.5.0
26/06/2026
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions <= 8.4.1 – Missing Authorization
The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…
*-8.4.1
8.4.2
01/06/2026
Stripe Payment Forms <= 8.3.1 – Unauthenticated SQL Injection
The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection via the 'wpfs-form-name' parameter in all versions up to, and including, 8.3.1 due to…
*-8.3.1
8.3.2
24/10/2025
WP Full Stripe Free <= 8.2.5 – Authenticated (Administrator+) SQL Injection
The WP Full Stripe Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-8.2.5
8.2.6
05/09/2025
WP Full Stripe Free <= 7.0.17 – Cross-Site Request Forgery
The WP Full Stripe Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.17. This is due to missing or incorrect nonce validation via several functions in the ~/include/wp-full-stripe-admin-menu.php file. This…
*-7.0.17
7.0.18
08/11/2023
WP Full Stripe Free <= 7.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.5 due to insufficient input sanitization and output escaping. This makes it possible for…
*-7.0.5
7.0.6
17/10/2023
WP Full Stripe Free <= 7.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-7.0.5
7.0.6
05/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.