Unauthenticated Payment Manipulation in WP Full Pay Stripe Plugin
CVE-2026-16734
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-16734?
The Stripe Payment Forms plugin by WP Full Pay prior to version 8.5.2 fails to validate ownership of payment intents for certain unauthenticated AJAX actions. This oversight allows malicious users to manipulate payment amounts by utilizing a nonce embedded in public pages. Although an ownership verification was introduced in version 8.5.0 for one payment-intent handler, critical actions regarding pricing recalculations and updates remain vulnerable, posing significant security risks to merchants relying on this plugin.
Affected Version(s)
Stripe Payment Forms by WP Full Pay 0 < 8.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.