Reflected Cross-Site Scripting Vulnerability in Payment Plugins for Stripe WooCommerce
CVE-2026-89100

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-89100?

The Payment Plugins for Stripe WooCommerce plugin is vulnerable to reflected cross-site scripting (XSS) attacks via the '#response' URL fragment. This issue arises in all versions up to and including 4.0.17, primarily due to inadequate input sanitization and output escaping mechanisms. Attackers can exploit this flaw to inject arbitrary web scripts that execute in the context of a user's browser upon accessing a compromised page. Exploitation is particularly straightforward when the 'Generic Errors' setting is toggled off, allowing the function getErrorMessage() to reveal unmodified error messages directly from Stripe.

Affected Version(s)

Payment Plugins for Stripe WooCommerce 0 <= 4.0.17

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.