CyberRota Analysis
AI-GeneratedThe Accept Stripe Payments plugin for WordPress versions prior to 2.1.4 is vulnerable due to inadequate validation of user-supplied URLs, enabling unauthenticated attackers to perform open redirects. This flaw can be exploited to redirect users to malicious external sites, potentially facilitating phishing attacks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.