Cross Site Scripting Vulnerability in WP Full Stripe Free by WordPress
CVE-2026-61960
7.1HIGH
What is CVE-2026-61960?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in WP Full Stripe Free versions up to 8.5.0. This flaw can potentially allow attackers to inject malicious scripts into web pages viewed by users, leading to session hijacking or malicious redirection. Website owners using this plugin are strongly advised to update to the latest version to mitigate potential risks.
Affected Version(s)
WP Full Stripe Free <= 8.5.0