plugin

Stripe Payments Vulnerabilities

14 known security issues reported for the Stripe Payments WordPress plugin. Most recent disclosed May 29, 2026.

6 medium

Running Stripe Payments on your site? Check whether your installed version is affected.

Scan your site free

Accept Stripe Payments <= 2.0.98 - Unauthenticated Payment Bypass

medium

The Accept Stripe Payments plugin for WordPress is vulnerable to Payment Bypasses in all versions up to, and including, 2.0.98. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 2.0.98
Fixed in:
2.0.99
Disclosed:
May 29, 2026

CVE-2026-42752 on NVD →

Accept Stripe Payments [stripe-payments] < 2.0.80

unknown

[en] Missing Authorization vulnerability in Tips and Tricks HQ, wptipsntricks Stripe Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through 2.0.79.

Affected:
up to 2.0.80
Fixed in:
2.0.80
Disclosed:
Dec 9, 2024

CVE-2023-48286 on NVD →

Accept Stripe Payments [stripe-payments] < 2.0.87

unknown

[en] The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

Affected:
up to 2.0.87
Fixed in:
2.0.87
Disclosed:
Aug 7, 2024

CVE-2024-7353 on NVD →

Accept Stripe Payments <= 2.0.86 - Authenticated (Contributor+) Stored Cross-Site Scripting via accept_stripe_payment_ng Shortcode

medium

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

CVSS:
5.4
Affected:
up to 2.0.86
Fixed in:
2.0.87
Disclosed:
Aug 6, 2024

CVE-2024-7353 on NVD →

Accept Stripe Payments [stripe-payments] < 2.0.80

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

Affected:
up to 2.0.80
Fixed in:
2.0.80
Disclosed:
Jun 4, 2024

CVE-2023-48285 on NVD →

Accept Stripe Payments <= 2.0.79 - Unauthenticated Content Injection

medium

The Accept Stripe Payments plugin for WordPress is vulnerable to Content Injection in all versions up to, and including, 2.0.79. This is due to payment data not properly being sanitized in the get_billing_details() function. This makes it possible for unauthenticated attackers to inject arbitrary content into pages.

CVSS:
5.3
Affected:
up to 2.0.79
Fixed in:
2.0.80
Disclosed:
Nov 23, 2023

CVE-2023-48285 on NVD →

Accept Stripe Payments <= 2.0.79 - Insecure Direct Object Reference

medium

The Stripe Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_create_pi() function in versions up to, and including, 2.0.79. This makes it possible for unauthenticated attackers to purchase products in another currency which may result in att...

CVSS:
5.3
Affected:
up to 2.0.79
Fixed in:
2.0.80
Disclosed:
Nov 23, 2023

CVE-2023-48286 on NVD →

Accept Stripe Payments [stripe-payments] < 2.0.64

unknown

[en] The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 2.0.64
Fixed in:
2.0.64
Disclosed:
Jul 17, 2022

CVE-2022-2194 on NVD →

Accept Stripe Payments <= 2.0.63 - Authenticated Stored Cross-Site Scripting

medium

The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 2.0.63
Fixed in:
2.0.64
Disclosed:
Jun 27, 2022

CVE-2022-2194 on NVD →

Accept Stripe Payments [stripe-payments] < 2.0.54

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Accept Stripe Payments plugin (versions <= 2.0.53).

Affected:
up to 2.0.54
Fixed in:
2.0.54
Disclosed:
Mar 14, 2022

Accept Stripe Payments [stripe-payments] < 2.0.40

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Park Won Seok in WordPress Stripe Payments plugin (versions <= 2.0.39).

Affected:
up to 2.0.40
Fixed in:
2.0.40
Disclosed:
Jan 8, 2021

Accept Stripe Payments < 2.0.40 - Authenticated Stored Cross-Site Scripting

medium

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘currency_code’ parameter in versions up to, and including, 2.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 2.0.40
Fixed in:
2.0.40
Disclosed:
Jan 5, 2021

Accept Stripe Payments [stripe-payments] < 2.0.40

unknown

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘currency_code’ parameter in versions up to, and including, 2.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.0.40
Fixed in:
2.0.40
Disclosed:
Jan 5, 2021

Accept Stripe Payments [stripe-payments] < 2.0.40

unknown

The Stripe Payments WordPress plugin, version 2.0.39 and possibly below, was vulnerable to Stored Cross-Site Scripting (XSS) in the plugin&#039;s currency_code settings parameter. The form did require a valid CSRF nonce, limiting the exploitability of the vulnerability.

Affected:
up to 2.0.40
Fixed in:
2.0.40

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database