CVE-2026-77758 PUBLISHED

Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session

Assigner: WPScan
Reserved: 21.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.

Product Status

Vendor Unknown
Product Stripe Payment Forms by WP Full Pay
Versions Default: unaffected
  • affected from 0 to 8.5.1 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE