SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81424

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Accept Stripe Payments WordPress plugin prior to version 2.1.4 is vulnerable due to inadequate verification of product fulfillment during checkout, allowing unauthenticated attackers to exploit this flaw. By completing a legitimate payment, they can receive fulfillment for a different product of equal or lesser value than what was actually purchased. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized product fulfillment.

CVE
CVE-2026-81424
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.