Code Injection Vulnerability in Easy Stripe by Scott Paterson
CVE-2025-49302

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 July 2025

What is CVE-2025-49302?

A code injection vulnerability has been identified in the Easy Stripe plugin developed by Scott Paterson, allowing potential attackers to execute arbitrary code remotely. This risk is present in versions from n/a through 1.1. It is crucial for website administrators using this plugin to assess their systems and implement necessary security measures to mitigate the risk associated with this vulnerability. Regular updates and awareness of security advisories can help protect against such vulnerabilities.

Affected Version(s)

Easy Stripe <= 1.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.
CVE-2025-49302 : Code Injection Vulnerability in Easy Stripe by Scott Paterson