Beveiligingsadvies

CVE-2026-77758

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-26 06:00:22
Laatst bijgewerkt 2026-08-26 14:43:07
Toegewezen door WPScan
CVSS-score 5.3
Status PUBLISHED

Beschrijving

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information.