GHSA-rvj6-j43w-hcgwMediumCVSS 4.3

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL...

Published
September 5, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.

🔗 References (3)