Broken Authentication in WP Full Stripe Free Plugin by WordPress
CVE-2026-42378
6.5MEDIUM
What is CVE-2026-42378?
The WP Full Stripe Free plugin for WordPress, specifically in versions up to 8.4.1, is exposed to a broken authentication vulnerability. This flaw could allow unauthorized access, enabling attackers to bypass standard authentication measures. Users should promptly update their plugin to mitigate possible exploitation and protect sensitive user information.
Affected Version(s)
WP Full Stripe Free <= 8.4.1