Extension WordPress

Vulnérabilités Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

Cette page rassemble les failles publiées pour Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

7 fiches

CVE-2026-12432 Moyenne · 5,3
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

Stripe Payment Forms by WP Full Pay <= 8.4.3 – Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…

Versions affectées

*-8.4.3

Correctif

8.5.0

Publication

26/06/2026

CVE-2026-42378 Moyenne · 4,3
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions <= 8.4.1 – Missing Authorization

The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…

Versions affectées

*-8.4.1

Correctif

8.4.2

Publication

01/06/2026

CVE-2025-9322 Élevée · 7,5
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

Stripe Payment Forms <= 8.3.1 – Unauthenticated SQL Injection

The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection via the 'wpfs-form-name' parameter in all versions up to, and including, 8.3.1 due to…

Versions affectées

*-8.3.1

Correctif

8.3.2

Publication

24/10/2025

CVE-2025-58789 Moyenne · 4,9
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

WP Full Stripe Free <= 8.2.5 – Authenticated (Administrator+) SQL Injection

The WP Full Stripe Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

Versions affectées

*-8.2.5

Correctif

8.2.6

Publication

05/09/2025

CVE-2023-47667 Moyenne · 4,3
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

WP Full Stripe Free <= 7.0.17 – Cross-Site Request Forgery

The WP Full Stripe Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.17. This is due to missing or incorrect nonce validation via several functions in the ~/include/wp-full-stripe-admin-menu.php file. This…

Versions affectées

*-7.0.17

Correctif

7.0.18

Publication

08/11/2023

CVE-2023-46088 Moyenne · 4,4
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

WP Full Stripe Free <= 7.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.5 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-7.0.5

Correctif

7.0.6

Publication

17/10/2023

CVE-2023-28934 Moyenne · 4,4
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

WP Full Stripe Free <= 7.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WP Full Stripe Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-7.0.5

Correctif

7.0.6

Publication

05/07/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités