SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81423

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Accept Stripe Payments plugin for WordPress versions prior to 2.1.4 is vulnerable due to inadequate validation of user-supplied URLs, enabling unauthenticated attackers to perform open redirects. This flaw can be exploited to redirect users to malicious external sites, potentially facilitating phishing attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-81423
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%
WordPress

Original NVD Description

The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.