Payment Page | Payment Form for Stripe <= 1.4.6 - Authenticated (Author+) Stored Cross-Site Scripting via 'pricing_plan_select_text_font_family' Parameter
medium
The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- Feb 13, 2026
CVE-2026-0751 on NVD →
Payment Page | Payment Form for Stripe [payment-page] < 1.1.1
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Payment Page plugin (versions <= 1.1).
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Feb 28, 2022
Payment Page | Payment Form for Stripe [payment-page] < 1.1.1
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Payment Page plugin (versions <= 1.1).
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Feb 28, 2022
Payment Page | Payment Form for Stripe [payment-page] < 1.2.9
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database