Payment Verification Flaw in Accept Stripe Payments Plugin by WordPress
CVE-2026-81424

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-81424?

The Accept Stripe Payments plugin for WordPress prior to version 2.1.4 lacks proper verification during the checkout process. Specifically, it does not ensure that the product fulfilled matches the actual purchase. Instead, it only checks if the amount paid meets or exceeds the product's price, which exposes the system to exploitation by unauthenticated individuals. By completing a legitimate transaction, attackers can receive fulfillment for a different product that is equal to or lower-priced than the one they purchased, potentially leading to unauthorized product distribution.

Affected Version(s)

Accept Stripe Payments 0 < 2.1.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Huu Do
WPScan
.