WordPress Plugin Vulnerabilities

Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR

Description

The plugin does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.

Proof of Concept

Affects Plugins

Fixed in 2.1.4

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Nguyen Huu Do
Submitter
Nguyen Huu Do
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other