CVE-2026-81423 PUBLISHED

Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler

Assigner: WPScan
Reserved: 26.08.2026 Published: 05.09.2026 Updated: 05.09.2026

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.

Product Status

Vendor Unknown
Product Accept Stripe Payments
Versions Default: unaffected
  • affected from 0 to 2.1.4 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE